CVE-2020-18900
LOW 3.3EPSS 0.3%
A heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128. NOTE: the vendor has disputed this as described in libyal/libexe issue 1 on GitHub
- CVSS v3.1
- 3.3 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L - CVSS v3.1
- 3.3 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L - CVSS v2.0
- 1.9 LOW
AV:L/AC:M/Au:N/C:N/I:N/A:P - EPSS
- 0.32% chance of exploitation in the next 30 days, 24th percentile
- Published
- 2021-08-19
- Updated
- 2024-08-04