Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27814

Опубликовано: 26 янв. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:*
Версия до 1.5.1 (включая)
cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.4.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00255
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

CVSS3: 7.8
redhat
больше 4 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

CVSS3: 7.8
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
больше 4 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain ...

CVSS3: 7.8
github
около 3 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

EPSS

Процентиль: 49%
0.00255
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-122