CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-40262

    Last Modified: 21 Nov 2024

    A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in PluginRAW.cpp.

    Published: 22 Aug 2023
    8.8
    High

    CVE-2021-40263

    Last Modified: 21 Nov 2024

    A heap overflow vulnerability in FreeImage 1.18.0 via the ofLoad function in PluginTIFF.cpp.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2021-40264

    Last Modified: 21 Nov 2024

    NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2021-46179

    Last Modified: 11 Apr 2025

    Reachable Assertion vulnerability in upx before 4.0.0 allows attackers to cause a denial of service via crafted file passed to the the readx function.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2023-34853

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.

    Published: 22 Aug 2023
    9.8
    Critical

    CVE-2022-48174

    Last Modified: 18 Dec 2025

    There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2020-18382

    Last Modified: 21 Nov 2024

    Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-opt.

    Published: 22 Aug 2023
    8.8
    High

    CVE-2020-18494

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2020-18651

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in function ID3_Support::ID3v2Frame::getFrameValue in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted audio file with ID3V2 frame.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2020-18652

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in WEBP_Support.cpp in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted webp file.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2020-18831

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2020-19725

    Last Modified: 21 Nov 2024

    There is a use-after-free vulnerability in file pdd_simplifier.cpp in Z3 before 4.8.8. It occurs when the solver attempt to simplify the constraints and causes unexpected memory access. It can cause segmentation faults or arbitrary code execution.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2020-21426

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2020-21427

    Last Modified: 5 May 2025

    Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2020-21428

    Last Modified: 2 May 2025

    Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

    Published: 22 Aug 2023
    4.4
    Medium

    CVE-2020-21469

    Last Modified: 21 Nov 2024

    An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).

    Published: 22 Aug 2023
    6.7
    Medium

    CVE-2020-21583

    Last Modified: 20 Dec 2024

    An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2020-21722

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in oggvideotools 0.9.1 allows remote attackers to run arbitrary code via opening of crafted ogg file.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2020-21723

    Last Modified: 21 Nov 2024

    A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remote attackers to cause a denial of service (crash) via opening of crafted ogg file.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2020-21890

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document.

    Published: 22 Aug 2023
    6.1
    Medium

    CVE-2020-22181

    Last Modified: 21 Nov 2024

    A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2020-22524

    Last Modified: 5 May 2025

    Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2020-22570

    Last Modified: 21 Nov 2024

    Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.

    Published: 22 Aug 2023
    9.1
    Critical

    CVE-2020-24113

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive information and cause a denial of service (DoS).

    Published: 22 Aug 2023
    7.5
    High

    CVE-2020-26652

    Last Modified: 21 Nov 2024

    An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.

    Published: 22 Aug 2023
    4.7
    Medium

    CVE-2022-47022

    Last Modified: 21 Nov 2024

    An issue was discovered in open-mpi hwloc 2.1.0 allows attackers to cause a denial of service or other unspecified impacts via glibc-cpuset in topology-linux.c.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2023-38666

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-25024

    Last Modified: 21 Nov 2024

    The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.

    Published: 22 Aug 2023
    8.8
    High

    CVE-2022-26592

    Last Modified: 21 Nov 2024

    Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-28069

    Last Modified: 21 Nov 2024

    A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-28070

    Last Modified: 21 Nov 2024

    A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-28071

    Last Modified: 21 Nov 2024

    A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-28072

    Last Modified: 21 Nov 2024

    A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-28073

    Last Modified: 21 Nov 2024

    A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2021-32421

    Last Modified: 21 Nov 2024

    dpic 2021.01.01 has a Heap Use-After-Free in thedeletestringbox() function in dpic.y.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2021-32422

    Last Modified: 21 Nov 2024

    dpic 2021.01.01 has a Global buffer overflow in theyylex() function in main.c and reads out of the bound array.

    Published: 22 Aug 2023
    10
    Critical

    CVE-2022-36648

    Last Modified: 21 Nov 2024

    The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. Note: This has been disputed by multiple third parties as not a valid vulnerability due to the rocker device not falling within the virtualization use case.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2021-40266

    Last Modified: 21 Nov 2024

    FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2021-43171

    Last Modified: 21 Nov 2024

    Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-48570

    Last Modified: 21 Nov 2024

    Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outside of the allocation if the allocated memory was not 16-byte aligned. NOTE: this issue exists because the CVE-2019-14318 fix was intentionally removed for functionality reasons.

    Published: 22 Aug 2023
    8.8
    High

    CVE-2020-18232

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.

    Published: 22 Aug 2023
    3.3
    Low

    CVE-2020-19909

    Last Modified: 21 Nov 2024

    Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties report that this has no direct security impact on the curl user; however, it may (in theory) cause a denial of service to associated systems or networks if, for example, --retry-delay is misinterpreted as a value much smaller than what was intended. This is not especially plausible because the overflow only happens if the user was trying to specify that curl should wait weeks (or longer) before trying to recover from a transient error.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2020-20813

    Last Modified: 21 Nov 2024

    Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2020-21047

    Last Modified: 21 Nov 2024

    The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2020-21699

    Last Modified: 21 Nov 2024

    The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.

    Published: 22 Aug 2023
    5.9
    Medium

    CVE-2020-22217

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2020-22219

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2020-22628

    Last Modified: 5 May 2025

    Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.

    Published: 22 Aug 2023
    8.6
    High

    CVE-2020-23793

    Last Modified: 21 Nov 2024

    An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.

    Published: 22 Aug 2023
    6.1
    Medium

    CVE-2020-23992

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.

    Published: 22 Aug 2023