Show filters
33 Total Results
Displaying 21-30 of 33
Sort by:
Attacker Value
Unknown

CVE-2022-25514

Disclosure Date: March 17, 2022 (last updated November 08, 2023)
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
Attacker Value
Unknown

CVE-2021-42716

Disclosure Date: October 21, 2021 (last updated February 23, 2025)
An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location.
Attacker Value
Unknown

CVE-2021-42715

Disclosure Date: October 21, 2021 (last updated February 23, 2025)
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files.
Attacker Value
Unknown

CVE-2020-6621

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.
Attacker Value
Unknown

CVE-2020-6617

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
Attacker Value
Unknown

CVE-2020-6620

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.
Attacker Value
Unknown

CVE-2020-6623

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.
Attacker Value
Unknown

CVE-2020-6622

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.
Attacker Value
Unknown

CVE-2020-6618

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.
Attacker Value
Unknown

CVE-2020-6619

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.