Show filters
52 Total Results
Displaying 21-30 of 52
Sort by:
Attacker Value
Unknown

CVE-2021-25293

Disclosure Date: March 19, 2021 (last updated February 22, 2025)
An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.
Attacker Value
Unknown

CVE-2021-25292

Disclosure Date: March 19, 2021 (last updated February 22, 2025)
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.
Attacker Value
Unknown

CVE-2021-27923

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Attacker Value
Unknown

CVE-2021-27921

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
Attacker Value
Unknown

CVE-2021-27922

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
Attacker Value
Unknown

CVE-2020-35653

Disclosure Date: January 12, 2021 (last updated February 22, 2025)
In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.
Attacker Value
Unknown

CVE-2020-35654

Disclosure Date: January 12, 2021 (last updated February 22, 2025)
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
Attacker Value
Unknown

CVE-2020-35655

Disclosure Date: January 12, 2021 (last updated February 22, 2025)
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
Attacker Value
Unknown

CVE-2020-10177

Disclosure Date: June 25, 2020 (last updated February 21, 2025)
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
Attacker Value
Unknown

CVE-2020-10379

Disclosure Date: June 25, 2020 (last updated February 21, 2025)
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.