Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-35655

In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.1%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 5.8
Products affected by CVE-2020-35655
  • Python » Pillow » Version: 4.3.0
    cpe:2.3:a:python:pillow:4.3.0
  • Python » Pillow » Version: 5.0.0
    cpe:2.3:a:python:pillow:5.0.0
  • Python » Pillow » Version: 5.1.0
    cpe:2.3:a:python:pillow:5.1.0
  • Python » Pillow » Version: 5.2.0
    cpe:2.3:a:python:pillow:5.2.0
  • Python » Pillow » Version: 5.3.0
    cpe:2.3:a:python:pillow:5.3.0
  • Python » Pillow » Version: 5.4.0
    cpe:2.3:a:python:pillow:5.4.0
  • Python » Pillow » Version: 5.4.1
    cpe:2.3:a:python:pillow:5.4.1
  • Python » Pillow » Version: 6.0.0
    cpe:2.3:a:python:pillow:6.0.0
  • Python » Pillow » Version: 6.2.0
    cpe:2.3:a:python:pillow:6.2.0
  • Python » Pillow » Version: 6.2.2
    cpe:2.3:a:python:pillow:6.2.2
  • Python » Pillow » Version: 6.2.3
    cpe:2.3:a:python:pillow:6.2.3
  • Python » Pillow » Version: 7.0.0
    cpe:2.3:a:python:pillow:7.0.0
  • Python » Pillow » Version: 7.1.0
    cpe:2.3:a:python:pillow:7.1.0
  • Python » Pillow » Version: 7.1.1
    cpe:2.3:a:python:pillow:7.1.1
  • Python » Pillow » Version: 7.1.2
    cpe:2.3:a:python:pillow:7.1.2
  • Python » Pillow » Version: 7.2.0
    cpe:2.3:a:python:pillow:7.2.0
  • Python » Pillow » Version: 8.0.0
    cpe:2.3:a:python:pillow:8.0.0
  • Python » Pillow » Version: 8.0.1
    cpe:2.3:a:python:pillow:8.0.1
  • Fedoraproject » Fedora » Version: 32
    cpe:2.3:o:fedoraproject:fedora:32
  • Fedoraproject » Fedora » Version: 33
    cpe:2.3:o:fedoraproject:fedora:33


Contact Us

Shodan ® - All rights reserved