Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27814

Опубликовано: 26 янв. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:*
Версия до 1.5.1 (включая)
cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.4.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00195
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 5 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

CVSS3: 7.8
redhat
почти 5 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

CVSS3: 7.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 5 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain ...

CVSS3: 7.8
github
больше 3 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

EPSS

Процентиль: 42%
0.00195
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-122