CVE-2019-17543High· 8.1▾ TwilightLZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor s…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 1.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.1%
LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."
lz4 < 1.9.2Upgrade past the affected range:
lz4 1.9.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-3520Critical· 9.8There's a flaw in lz4
CVE-2021-33656Medium· 6.8When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.
CVE-2022-2129High· 7.8Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
CVE-2020-14390Medium· 5.6A flaw was found in the Linux kernel in versions before 5.9-rc6
CVE-2022-48423High· 7.8In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names
CVE-2022-0995High· 7.8An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem