CVE-2020-27842
- EPSS 0.07%
- Veröffentlicht 05.01.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:21:54
There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.
CVE-2020-27843
- EPSS 0.08%
- Veröffentlicht 05.01.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:21:55
A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system ...
CVE-2020-27845
- EPSS 0.07%
- Veröffentlicht 05.01.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:21:55
There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw ...
CVE-2020-27841
- EPSS 0.08%
- Veröffentlicht 05.01.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:54
There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to...
CVE-2020-36158
- EPSS 0.58%
- Veröffentlicht 05.01.2021 05:15:10
- Zuletzt bearbeitet 21.11.2024 05:28:50
mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.
CVE-2019-25013
- EPSS 0.63%
- Veröffentlicht 04.01.2021 18:15:13
- Zuletzt bearbeitet 09.06.2025 16:15:30
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.
CVE-2020-24386
- EPSS 0.63%
- Veröffentlicht 04.01.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:14:43
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
CVE-2020-25275
- EPSS 6.85%
- Veröffentlicht 04.01.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:17:50
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
CVE-2020-35496
- EPSS 0.05%
- Veröffentlicht 04.01.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:27:25
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to applicat...
CVE-2020-35494
- EPSS 0.21%
- Veröffentlicht 04.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:25
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to da...