Show filters
52 Total Results
Displaying 31-40 of 52
Sort by:
Attacker Value
Unknown

CVE-2020-10378

Disclosure Date: June 25, 2020 (last updated February 21, 2025)
In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.
Attacker Value
Unknown

CVE-2020-10994

Disclosure Date: June 25, 2020 (last updated February 21, 2025)
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
Attacker Value
Unknown

CVE-2020-11538

Disclosure Date: June 25, 2020 (last updated February 21, 2025)
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
Attacker Value
Unknown

CVE-2020-5311

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
Attacker Value
Unknown

CVE-2020-5310

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
Attacker Value
Unknown

CVE-2020-5312

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
Attacker Value
Unknown

CVE-2020-5313

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
Attacker Value
Unknown

CVE-2019-16865

Disclosure Date: April 17, 2019 (last updated November 08, 2023)
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
Attacker Value
Unknown

CVE-2019-19911

Disclosure Date: February 28, 2019 (last updated February 21, 2025)
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
Attacker Value
Unknown

CVE-2016-3076

Disclosure Date: April 24, 2017 (last updated November 26, 2024)
Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
0