CVE-2020-36278
- EPSS 0.54%
- Veröffentlicht 12.03.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:11
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
CVE-2020-36279
- EPSS 4.25%
- Veröffentlicht 12.03.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:11
Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
CVE-2020-36280
- EPSS 1.75%
- Veröffentlicht 12.03.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:11
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.
CVE-2021-28153
- EPSS 0.57%
- Veröffentlicht 11.03.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:59:11
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which coul...
CVE-2020-36277
- EPSS 6.65%
- Veröffentlicht 11.03.2021 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:11
Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
CVE-2021-21381
- EPSS 0.12%
- Veröffentlicht 11.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:14
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to ga...
CVE-2021-27919
- EPSS 0.13%
- Veröffentlicht 11.03.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:58:48
archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename.
CVE-2021-21334
- EPSS 0.36%
- Veröffentlicht 10.03.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:02
In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) ...
CVE-2021-20205
- EPSS 0.44%
- Veröffentlicht 10.03.2021 17:15:15
- Zuletzt bearbeitet 21.11.2024 05:46:07
Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.
CVE-2021-21772
- EPSS 1.67%
- Veröffentlicht 10.03.2021 17:15:15
- Zuletzt bearbeitet 21.11.2024 05:48:56
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerab...