Libass Project Libass vulnerabilities

6 known vulnerabilities affecting libass_project/libass.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6

Vulnerabilities

Page 1 of 1
CVE-2020-36430HIGHCVSS 7.8≥ 0.15.0, < 0.15.12021-07-20
CVE-2020-36430 [HIGH] CWE-787 CVE-2020-36430: libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_fon libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
nvdosv
CVE-2020-24994HIGHCVSS 8.8fixed in 0.15.02021-03-23
CVE-2020-24994 [HIGH] CWE-770 CVE-2020-24994: Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service or remote code execution via a crafted file.
nvdosv
CVE-2020-26682HIGHCVSS 8.8v0.14.02020-10-16
CVE-2020-26682 [HIGH] CWE-190 CVE-2020-26682: In libass 0.14.0, the `ass_outline_construct`'s call to `outline_stroke` causes a signed integer ove In libass 0.14.0, the `ass_outline_construct`'s call to `outline_stroke` causes a signed integer overflow.
nvdosv
CVE-2016-7969HIGHCVSS 7.5≤ 0.13.32017-03-03
CVE-2016-7969 [HIGH] CWE-125 CVE-2016-7969: The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cau The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."
nvdosv
CVE-2016-7970HIGHCVSS 7.5≤ 0.13.32017-03-03
CVE-2016-7970 [HIGH] CWE-119 CVE-2016-7970: Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remot Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors.
nvdosv
CVE-2016-7972HIGHCVSS 7.5≤ 0.13.32017-03-03
CVE-2016-7972 [HIGH] CWE-399 CVE-2016-7972: The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attacker The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
nvdosv