Show filters
49 Total Results
Displaying 1-10 of 49
Sort by:
Attacker Value
Moderate

CVE-2020-15900

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.
Attacker Value
Unknown

CVE-2021-31956

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
Windows NTFS Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2021-20240

Disclosure Date: May 28, 2021 (last updated February 22, 2025)
A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Attacker Value
Unknown

CVE-2021-31178

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
Microsoft Office Information Disclosure Vulnerability
0
Attacker Value
Unknown

CVE-2021-25846

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a negative number passed to the memcpy function via a crafted lldp packet.
Attacker Value
Unknown

CVE-2021-25849

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper validation of the PortID TLV leads to Denial of Service via a crafted lldp packet.
Attacker Value
Unknown

CVE-2021-3472

Disclosure Date: April 26, 2021 (last updated February 22, 2025)
A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Attacker Value
Unknown

CVE-2021-27486

Disclosure Date: April 12, 2021 (last updated February 22, 2025)
FATEK Automation WinProladder Versions 3.30 and prior is vulnerable to an integer underflow, which may cause an out-of-bounds write and allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-28362

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
An issue was discovered in Contiki through 3.0. When sending an ICMPv6 error message because of invalid extension header options in an incoming IPv6 packet, there is an attempt to remove the RPL extension headers. Because the packet length and the extension header length are unchecked (with respect to the available data) at this stage, and these variables are susceptible to integer underflow, it is possible to construct an invalid extension header that will cause memory corruption issues and lead to a Denial-of-Service condition. This is related to rpl-ext-header.c.
Attacker Value
Unknown

CVE-2021-28027

Disclosure Date: March 05, 2021 (last updated February 22, 2025)
An issue was discovered in the bam crate before 0.1.3 for Rust. There is an integer underflow and out-of-bounds write during the loading of a bgzip block.