|
197601
|
5.5 |
MEDIUM
Local
|
unicorn-engine
|
unicorn_engine
|
Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36431
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197602
|
7.8 |
HIGH
Local
|
libass_project fedoraproject
|
libass fedora
|
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36430
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197603
|
5.5 |
MEDIUM
Local
|
open62541
|
open62541
|
Variant_encodeJson in open62541 1.x before 1.0.4 has an out-of-bounds write for a large recursion depth.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36429
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197604
|
8.8 |
HIGH
Network
|
matio_project
|
matio
|
matio (aka MAT File I/O Library) 1.5.18 through 1.5.21 has a heap-based buffer overflow in ReadInt32DataDouble (called from ReadInt32Data and Mat_VarRead4).
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36428
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197605
|
5.5 |
MEDIUM
Local
|
gnome
|
gthumb
|
GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image.
|
NVD-CWE-noinfo
|
CVE-2020-36427
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197606
|
7.5 |
HIGH
Network
|
arm debian
|
mbed_tls debian_linux
|
An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).
|
CWE-125
Out-of-bounds Read
|
CVE-2020-36426
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197607
|
5.3 |
MEDIUM
Network
|
arm debian
|
mbed_tls debian_linux
|
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can …
|
CWE-295
Improper Certificate Validation
|
CVE-2020-36425
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197608
|
4.7 |
MEDIUM
Local
|
arm debian
|
mbed_tls debian_linux
|
An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblindin…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-36424
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197609
|
7.5 |
HIGH
Network
|
arm debian
|
mbed_tls debian_linux
|
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-36423
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197610
|
5.3 |
MEDIUM
Network
|
arm debian
|
mbed_tls debian_linux
|
An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbe…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-36422
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|