Show filters
39 Total Results
Displaying 21-30 of 39
Sort by:
Attacker Value
Unknown
CVE-2020-27790
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
A floating point exception issue was discovered in UPX in PackLinuxElf64::invert_pt_dynamic() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service. The highest impact is to Availability.
0
Attacker Value
Unknown
CVE-2020-27787
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.
0
Attacker Value
Unknown
CVE-2021-36924
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.
0
Attacker Value
Unknown
CVE-2021-36923
Disclosure Date: November 02, 2021 (last updated November 28, 2024)
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB device privileged IN and OUT instructions (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.
0
Attacker Value
Unknown
CVE-2021-36925
Disclosure Date: November 02, 2021 (last updated November 28, 2024)
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read or write operation from/to physical memory (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.
0
Attacker Value
Unknown
CVE-2021-36922
Disclosure Date: November 02, 2021 (last updated November 28, 2024)
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB devices (Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.
0
Attacker Value
Unknown
CVE-2021-30500
Disclosure Date: May 27, 2021 (last updated February 22, 2025)
Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.
0
Attacker Value
Unknown
CVE-2021-30501
Disclosure Date: May 27, 2021 (last updated February 22, 2025)
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.
0
Attacker Value
Unknown
CVE-2020-24119
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
0
Attacker Value
Unknown
CVE-2021-20285
Disclosure Date: March 26, 2021 (last updated February 22, 2025)
A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from this vulnerability is to system availability.
0