6.5
CVSSv3

CVE-2020-21600

Published: 16/09/2021 Updated: 11/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

struktur libde265 1.0.4

Vendor Advisories

Debian Bug report logs - #1004963 CVE-2020-21598 CVE-2020-21600 CVE-2020-21602 Package: src:libde265; Maintainer for src:libde265 is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 4 Feb 2022 12:18:02 UTC Severity: grave Tags: security, ...
libde265 v104 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file ...
Multiple security issues were discovered in libde265, an implementation of the H265 video codec which may result in denial of service and potentially the execution of arbitrary code if a malformed media file is processed For the stable distribution (bullseye), these problems have been fixed in version 1011-0+deb11u1 We recommend that you upgra ...

Github Repositories

CVE-2020-21600 Exploit libde265 v104 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file Windows Binary PoC /CVE-2020-21600exe will run the exploit /CVE-2020-21600exe -t Target IP /CVE-2020-21600exe -t wwwexamplecom Running the exploit on Linux Change t

CVE-2020-21600 libde265 v104 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file authentication complexity vector NONE MEDIUM NETWORK confidentiality integrity availability NONE NONE PARTIAL CVSS Score: 43 References strukturag/libde265#243 cwemitreorg/data/definitio

CVE-2020-21600 Exploit libde265 v104 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file Windows Binary PoC /CVE-2020-21600exe will run the exploit /CVE-2020-21600exe -t Target IP /CVE-2020-21600exe -t wwwexamplecom Running the exploit on Linux Change t