Lucene search

K
cvelistMitreCVELIST:CVE-2020-28248
HistoryFeb 19, 2021 - 11:05 p.m.

CVE-2020-28248

2021-02-1923:05:09
mitre
www.cve.org
2
integer overflow
png file
heap memory
buffer overflow

AI Score

8.8

Confidence

High

EPSS

0.005

Percentile

75.2%

An integer overflow in the PngImg::InitStorage_() function of png-img before 3.1.0 leads to an under-allocation of heap memory and subsequently an exploitable heap-based buffer overflow when loading a crafted PNG file.

AI Score

8.8

Confidence

High

EPSS

0.005

Percentile

75.2%

Related for CVELIST:CVE-2020-28248