CRITICAL9.8CVE-2020-5311Buffer Copy without Checking Size of Input in Pillow from 0, < 6.2.2
from 0, < 9.0.1
from 0, < 6.2.2
CRITICAL9.8Buffer Overflow in Pillow
>= 1.0.0, < 1.1.8, >= 1.2.0, < 8.2.1
CRITICAL9.8Out of bounds write in Pillow
from 0, < 8.1.1
CRITICAL9.1Path traversal in Pillow
from 0, < 9.0.1
CRITICAL9.1Pillow Out-of-bounds Read vulnerability
from 0, < 8.2.0
CRITICAL9.1Out-of-bounds Read in Pillow
from 0, < 8.2.0
HIGH8.8Integer overflow in Pillow
from 0, < 6.2.2
HIGH8.8Pillow Out-of-bounds Write
from 0, < 8.1.0
HIGH8.2Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
from 0, < 12.3.0
HIGH8.1Out-of-bounds read in Pillow
from 0, < 7.0.1
HIGH7.8Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)
>= 10.3.0, < 12.2.0
HIGH7.8Buffer overflow in Pillow
from 0, < 7.1.0
HIGH7.5Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
>= 5.1.0, < 12.3.0
HIGH7.5Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch
from 0, < 12.3.0
HIGH7.5Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
>= 8.2.0, < 12.3.0
HIGH7.5Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
from 0, < 12.3.0
HIGH7.5Pillow is vulnerable to a FITS GZIP decompression bomb
>= 10.3.0, < 12.2.0
HIGH7.5Pillow has an out-of-bounds write when loading PSD images
>= 10.3.0, < 12.1.1
HIGH7.5pillow - security update
from 0, < 10.0.0
HIGH7.5Pillow vulnerable to Data Amplification attack.
from 0, < 9.2.0
HIGH7.5Pillow subject to DoS via SAMPLESPERPIXEL tag
from 0, < 9.3.0
HIGH7.5Buffer over-flow in Pillow
>= 9.1.0, < 9.1.1
HIGH7.5Regular Expression Denial of Service (ReDoS)
>= 5.2.0, < 8.3.2
HIGH7.5Uncontrolled Resource Consumption in Pillow
from 0, < 8.2.0
HIGH7.5Potential infinite loop in Pillow
from 0, < 8.2.0
HIGH7.5Out of bounds read in Pillow
from 0, < 8.1.1
HIGH7.5Out-of-bounds Write in Pillow
from 0, < 8.1.1
HIGH7.5Out of bounds read in Pillow
from 0, < 8.1.1
HIGH7.5Pillow Uncontrolled Resource Consumption
from 0, < 8.1.1
HIGH7.5Pillow Denial of Service by Uncontrolled Resource Consumption
from 0, < 8.1.1
HIGH7.5Pillow Denial of Service by Uncontrolled Resource Consumption
from 0, < 8.1.1
HIGH7.1Pillow Vulnerable to Write Buffer Overflow on BCn encoding
>= 11.2.0
HIGH7.1pillow - security update
from 0, < 8.1.0
HIGH7.1Out-of-bounds Read in Pillow
from 0, < 6.2.2
MEDIUM6.5Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
>= 5.2.0, < 12.3.0
MEDIUM6.5pillow - security update
from 0, < 9.0.0
MEDIUM6.5Out-of-bounds Read in Pillow
from 0, < 9.0.0
MEDIUM6.5Regular Expression Denial of Service (ReDoS) in Pillow
from 0, < 8.1.1
MEDIUM5.9pillow - security update
from 0
MEDIUM5.5Pillow: PDF Parsing Trailer Infinite Loop (DoS)
>= 4.2.0, < 12.2.0
MEDIUM5.5Pillow: Integer overflow when processing fonts
from 0, < 12.2.0
MEDIUM5.5Pillow: Heap buffer overflow with nested list coordinates
>= 11.2.1, < 12.2.0
MEDIUM5.5Out-of-bounds read in Pillow
from 0, < 7.1.0
MEDIUM5.5Insufficient Verification of Data Authenticity in Pillow
from 0, < 8.2.0
MEDIUM5.5Pillow denial of service
from 0, < 8.2.0
MEDIUM5.5pillow - security update
from 0, < 7.1.0
MEDIUM5.5Out-of-bounds reads in Pillow
from 0, < 7.1.0
MEDIUM5.4Pillow Out-of-bounds Read
>= 4.3.0, < 8.1.0
MEDIUM5.3Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
>= 12.0.0, < 12.3.0
—Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
from 0, < 12.3.0