Vulnerabilities > Libass Project > Libass > 0.15.0

DATE CVE VULNERABILITY TITLE RISK
2021-07-20 CVE-2020-36430 Out-of-bounds Write vulnerability in multiple products
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
local
low complexity
libass-project fedoraproject CWE-787
7.8