6.4
CVSSv2

CVE-2020-36331

Published: 21/05/2021 Updated: 09/01/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

A flaw was found in libwebp in versions prior to 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webmproject libwebp

redhat enterprise linux 8.0

netapp ontap select deploy administration utility -

debian debian linux 9.0

debian debian linux 10.0

apple iphone os

apple ipados

Vendor Advisories

Synopsis Important: OpenShift Container Platform 4110 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4110 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Co ...
Multiple vulnerabilities were discovered in libwebp, the implementation of the WebP image format, which could result in denial of service, memory disclosure or potentially the execution of arbitrary code if malformed images are processed For the stable distribution (buster), these problems have been fixed in version 061-2+deb10u1 We recommend t ...
A flaw was found in libwebp in versions before 101 An out-of-bounds read was found in function ChunkVerifyAndAssign The highest threat from this vulnerability is to data confidentiality and to the service availability (CVE-2020-36330) A flaw was found in libwebp in versions before 101 An out-of-bounds read was found in function ChunkAssignD ...
A flaw was found in libwebp in versions before 101 An out-of-bounds read was found in function ChunkVerifyAndAssign The highest threat from this vulnerability is to data confidentiality and to the service availability (CVE-2020-36330) A flaw was found in libwebp in versions before 101 An out-of-bounds read was found in function ChunkAssignD ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-07-21-1 iOS 147 and iPadOS 147 iOS 147 and iPadOS 147 addresses the following issues Information about the security content is also available at supportapplecom/HT212601 iOS 147 released July 19, 2021; iPadOS 147 released July 21, 2021 ActionKit Available for: iPhon ...