CVE-2020-10177
- EPSS 0.12%
- Veröffentlicht 25.06.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:54:55
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
CVE-2020-10378
- EPSS 0.33%
- Veröffentlicht 25.06.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:11
In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.
CVE-2020-10379
- EPSS 0.4%
- Veröffentlicht 25.06.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:11
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
CVE-2020-10994
- EPSS 0.44%
- Veröffentlicht 25.06.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:32
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
CVE-2020-11538
- EPSS 0.43%
- Veröffentlicht 25.06.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:06
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
CVE-2020-5963
- EPSS 0.05%
- Veröffentlicht 25.06.2020 00:15:10
- Zuletzt bearbeitet 21.11.2024 05:34:54
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.
CVE-2020-12862
- EPSS 0.17%
- Veröffentlicht 24.06.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:26
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.
CVE-2020-12863
- EPSS 0.17%
- Veröffentlicht 24.06.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:26
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.
CVE-2020-12864
- EPSS 0.19%
- Veröffentlicht 24.06.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:26
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.
- EPSS 0.3%
- Veröffentlicht 24.06.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:26
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.