Search Results (40929 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-23922 2 Apache, Giflib Project 2 Bookkeeper, Giflib 2024-11-21 7.1 High
An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.
CVE-2020-23921 1 Fast Ber Project 1 Fast Ber 2024-11-21 7.1 High
An issue was discovered in fast_ber through v0.4. yy::yylex() in asn_compiler.hpp has a heap-based buffer over-read.
CVE-2020-23915 1 Cpp-peglib Project 1 Cpp-peglib 2024-11-21 5.5 Medium
An issue was discovered in cpp-peglib through v0.1.12. peg::resolve_escape_sequence() in peglib.h has a heap-based buffer over-read.
CVE-2020-23909 1 Advancemame 1 Advancemame 2024-11-21 7.1 High
Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1.
CVE-2020-23904 1 Xiph 1 Speex 2024-11-21 5.5 Medium
A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. NOTE: the vendor states "I cannot reproduce it" and it "is a demo program.
CVE-2020-23902 1 Wildbit-soft 1 Wildbit Viewer 2024-11-21 5.5 Medium
A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address may be used as a return value starting at Editor!TMethodImplementationIntercept+0x528a3.
CVE-2020-23900 1 Wildbit-soft 1 Wildbit Viewer 2024-11-21 5.5 Medium
A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address controls Code Flow starting at Editor!TMethodImplementationIntercept+0x57a3b.
CVE-2020-23890 1 Wildbit-soft 1 Wildbit Viewer 2024-11-21 5.5 Medium
A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted JPG file. Related to Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at JPGCodec+0x753648.
CVE-2020-23884 1 Nomacs 1 Nomacs 2024-11-21 5.5 Medium
A buffer overflow in Nomacs v3.15.0 allows attackers to cause a denial of service (DoS) via a crafted MNG file.
CVE-2020-23705 1 Rockcarry 1 Ffjpeg 2024-11-21 6.5 Medium
A global buffer overflow vulnerability in jfif_encode at jfif.c:701 of ffjpeg through 2020-06-22 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.
CVE-2020-23679 1 Linux Network Project 1 Linux Network Project 2024-11-21 9.8 Critical
Buffer overflow vulnerability in Renleilei1992 Linux_Network_Project 1.0, allows attackers to execute arbitrary code, via the password field.
CVE-2020-23574 1 Sysax 1 Multi Server 2024-11-21 6.5 Medium
When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This will create a buffer overflow condition, causing the application to crash.
CVE-2020-23563 1 Irfanview 1 Irfanview 2024-11-21 5.5 Medium
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba.
CVE-2020-23109 1 Struktur 1 Libheif 2024-11-21 8.1 High
Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.
CVE-2020-22886 1 Artifex 1 Mujs 2024-11-21 7.5 High
Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of service.
CVE-2020-22885 1 Artifex 1 Mujs 2024-11-21 7.5 High
Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of service.
CVE-2020-22884 1 Espruino 1 Espruino 2024-11-21 9.8 Critical
Buffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to execute arbitrary code.
CVE-2020-22876 1 Quickjs Project 1 Quickjs 2024-11-21 7.5 High
Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service. This issue is resolved in the 2020-07-05 release.
CVE-2020-22875 1 Jsish 1 Jsish 2024-11-21 9.8 Critical
Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.
CVE-2020-22874 1 Jsish 1 Jsish 2024-11-21 9.8 Critical
Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute arbitrary code.