CVE-2021-3695: GRUB2 PNG loader heap overflow in 16-bit grayscale conversion (d1 += 4 stride bug)

CVE-2021-3695: GRUB2 PNG 16-bit grayscale heap overflow (stride mismatch)

posted 3 months ago

GRUB2 PNG Loader Heap Buffer Overflow Due to Off-by-One in Size Calculation

CVE-2020-10713 BootHole: heap overflow in grub_script_lexer_record

CVE-2020-10713 BootHole: Integer Overflow → Heap Buffer Overflow in GRUB2 Script Lexer (grub-core/script/yylex.l)

CVE-2020-10713 GRUB2 BootHole: YY_FATAL_ERROR Non-Fatal Buffer Overflow

posted 3 months ago

CVE-2024-25062: use-after-free in libxml2 xmlTextReaderRead — missing BACKTRACK state guard on XInclude re-expansion

CVE-2024-25062 libxml2 use-after-free in xmlTextReaderValidateEntity

libxml2 CVE-2024-25062: Use-after-free in xmlTextReaderRead during DTD validation with XInclude

libxml2 CVE-2023-29469: Hash function fails to validate string length

posted 3 months ago

CVE-2021-3518: Use-after-free in libxml2 xmlXIncludeAddNode (xinclude.c)

CVE-2021-3518: Use-after-free in libxml2 XInclude recursive processing

posted 3 months ago

CVE-2022-40304: libxml2 dict corruption via entity reference cycle (ent->content[0]=0 on dict-owned memory)

CVE-2022-40304: libxml2 dict corruption from entity reference cycles

CVE-2022-40304: Dict Corruption via Entity Reference Cycles in libxml2

CVE-2022-40303: Integer overflow in libxml2 xmlSAX2Text → heap buffer overflow on large XML text nodes

CVE-2022-40303: libxml2 integer overflow with XML_PARSE_HUGE in xmlParseEntityValue and friends

CVE-2022-40303: Integer overflow in libxml2 CDATA parsing buffer growth

CVE-2023-0286: Type confusion in OpenSSL GENERAL_NAME_cmp for X.400 addresses — ASN1_STRING* parsed but treated as ASN1_TYPE*

CVE-2023-0286: X.509 GeneralName Type Confusion in OpenSSL 3.0.7