[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2020-21428":6},{"stargazers_count":4,"fetched_at":5},5,"2026-04-09T02:11:32.352Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":72,"aliases":73,"duplicate_of":9,"upstream":74,"downstream":75,"duplicates":88,"related":89,"reserved_at":9,"published_at":91,"modified_at":92,"state":93,"summary":94,"references_raw":103,"kevs":128,"epss":129,"epss_history":132,"metrics":393,"affected":405},"CVE-2020-21428","Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-120","Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')","The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.","weakness","Incomplete","Base","High",[20,24,28,32,36,40,44,48,52,56,60,64,68],{"id":21,"name":22,"techniques":23},"CAPEC-10","Buffer Overflow via Environment Variables",[],{"id":25,"name":26,"techniques":27},"CAPEC-100","Overflow Buffers",[],{"id":29,"name":30,"techniques":31},"CAPEC-14","Client-side Injection-induced Buffer Overflow",[],{"id":33,"name":34,"techniques":35},"CAPEC-24","Filter Failure through Buffer Overflow",[],{"id":37,"name":38,"techniques":39},"CAPEC-42","MIME Conversion",[],{"id":41,"name":42,"techniques":43},"CAPEC-44","Overflow Binary Resource File",[],{"id":45,"name":46,"techniques":47},"CAPEC-45","Buffer Overflow via Symbolic Links",[],{"id":49,"name":50,"techniques":51},"CAPEC-46","Overflow Variables and Tags",[],{"id":53,"name":54,"techniques":55},"CAPEC-47","Buffer Overflow via Parameter Expansion",[],{"id":57,"name":58,"techniques":59},"CAPEC-67","String Format Overflow in syslog()",[],{"id":61,"name":62,"techniques":63},"CAPEC-8","Buffer Overflow in an API Call",[],{"id":65,"name":66,"techniques":67},"CAPEC-9","Buffer Overflow in Local Command-Line Utilities",[],{"id":69,"name":70,"techniques":71},"CAPEC-92","Forced Integer Overflow",[],[],[],[],[76,78,80,82,84,86],{"_key":77},"DEBIAN-CVE-2020-21428",{"_key":79},"UBUNTU-CVE-2020-21428",{"_key":81},"USN-6586-1",{"_key":83},"OPENSUSE-SU-2024:13293-1",{"_key":85},"DLA-3662-1",{"_key":87},"DSA-5579-1",[],[90],{"_key":83},"2023-08-22T00:00:00.000Z","2025-05-02T15:29:46.961Z","Modified",{"cisa_kev":95,"cisa_ransomware":95,"cisa_vendor":9,"epss_severity":96,"epss_score":97,"severity":98,"severity_score":99,"severity_version":100,"severity_source":101,"severity_vector":102,"severity_status":93},false,"low",0.00061,"high",7.8,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",[104,110,115,119,124],{"url":105,"sources":106,"tags":108},"https://sourceforge.net/p/freeimage/bugs/299/",[107,101],"cve.org",[109],"Third Party Advisory",{"url":111,"sources":112,"tags":113},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RUEK2JOVJBQZVNQIIZZO3JFMTVB4R5KS/",[107,101],[114],"Vendor Advisory",{"url":116,"sources":117,"tags":118},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UGOMCRAANNCQYJYPPMGRQWKRZGIP6NME/",[107,101],[114],{"url":120,"sources":121,"tags":122},"https://lists.debian.org/debian-lts-announce/2023/11/msg00020.html",[107,101],[123],"Mailing List",{"url":125,"sources":126,"tags":127},"https://www.debian.org/security/2023/dsa-5579",[107,101],[114],[],{"date":130,"score":97,"percentile":131},"2026-04-08",0.19158,[133,136,139,142,145,148,151,154,157,160,163,166,168,171,174,178,181,184,187,190,193,196,199,202,204,207,210,213,216,219,222,225,228,231,234,237,240,243,246,249,252,255,258,261,264,267,270,273,276,279,281,284,287,290,292,295,298,301,304,307,310,313,315,317,320,323,326,329,332,335,337,340,343,346,348,351,354,357,359,362,365,368,370,373,376,379,381,384,387,390],{"date":134,"score":97,"percentile":135},"2025-11-04",0.19181,{"date":137,"score":97,"percentile":138},"2025-11-05",0.19192,{"date":140,"score":97,"percentile":141},"2025-11-06",0.192,{"date":143,"score":97,"percentile":144},"2025-11-07",0.19211,{"date":146,"score":97,"percentile":147},"2025-11-08",0.19212,{"date":149,"score":97,"percentile":150},"2025-11-09",0.19186,{"date":152,"score":97,"percentile":153},"2025-11-10",0.19141,{"date":155,"score":97,"percentile":156},"2025-11-11",0.19146,{"date":158,"score":97,"percentile":159},"2025-11-12",0.1919,{"date":161,"score":97,"percentile":162},"2025-11-13",0.19218,{"date":164,"score":97,"percentile":165},"2025-11-14",0.1921,{"date":167,"score":97,"percentile":150},"2025-11-15",{"date":169,"score":97,"percentile":170},"2025-11-16",0.19144,{"date":172,"score":97,"percentile":173},"2025-11-17",0.19071,{"date":175,"score":176,"percentile":177},"2025-11-18",0.0018,0.34957,{"date":179,"score":176,"percentile":180},"2025-11-19",0.34968,{"date":182,"score":176,"percentile":183},"2025-11-20",0.34946,{"date":185,"score":97,"percentile":186},"2025-11-21",0.19065,{"date":188,"score":97,"percentile":189},"2025-11-22",0.19067,{"date":191,"score":97,"percentile":192},"2025-11-23",0.19042,{"date":194,"score":97,"percentile":195},"2025-11-24",0.19007,{"date":197,"score":97,"percentile":198},"2025-11-25",0.18998,{"date":200,"score":97,"percentile":201},"2025-11-26",0.18993,{"date":203,"score":97,"percentile":201},"2025-11-27",{"date":205,"score":97,"percentile":206},"2025-11-28",0.18976,{"date":208,"score":97,"percentile":209},"2025-11-29",0.18968,{"date":211,"score":97,"percentile":212},"2025-11-30",0.18971,{"date":214,"score":97,"percentile":215},"2025-12-01",0.19015,{"date":217,"score":97,"percentile":218},"2025-12-02",0.19038,{"date":220,"score":97,"percentile":221},"2025-12-03",0.19054,{"date":223,"score":97,"percentile":224},"2025-12-04",0.19016,{"date":226,"score":97,"percentile":227},"2025-12-05",0.19068,{"date":229,"score":97,"percentile":230},"2025-12-06",0.1907,{"date":232,"score":97,"percentile":233},"2025-12-07",0.19055,{"date":235,"score":97,"percentile":236},"2025-12-08",0.19077,{"date":238,"score":97,"percentile":239},"2025-12-09",0.19145,{"date":241,"score":97,"percentile":242},"2025-12-10",0.19223,{"date":244,"score":97,"percentile":245},"2025-12-11",0.19265,{"date":247,"score":97,"percentile":248},"2025-12-12",0.19295,{"date":250,"score":97,"percentile":251},"2025-12-13",0.1931,{"date":253,"score":97,"percentile":254},"2025-12-14",0.1926,{"date":256,"score":97,"percentile":257},"2025-12-15",0.19241,{"date":259,"score":97,"percentile":260},"2025-12-16",0.19277,{"date":262,"score":97,"percentile":263},"2025-12-17",0.19358,{"date":265,"score":97,"percentile":266},"2025-12-18",0.19447,{"date":268,"score":97,"percentile":269},"2025-12-19",0.19467,{"date":271,"score":97,"percentile":272},"2025-12-20",0.19441,{"date":274,"score":97,"percentile":275},"2025-12-21",0.19402,{"date":277,"score":97,"percentile":278},"2025-12-22",0.19356,{"date":280,"score":97,"percentile":263},"2025-12-23",{"date":282,"score":97,"percentile":283},"2025-12-24",0.19399,{"date":285,"score":97,"percentile":286},"2025-12-25",0.19477,{"date":288,"score":97,"percentile":289},"2025-12-26",0.19471,{"date":291,"score":97,"percentile":269},"2025-12-27",{"date":293,"score":97,"percentile":294},"2025-12-28",0.19427,{"date":296,"score":97,"percentile":297},"2025-12-29",0.1938,{"date":299,"score":97,"percentile":300},"2025-12-30",0.19372,{"date":302,"score":97,"percentile":303},"2025-12-31",0.19432,{"date":305,"score":97,"percentile":306},"2026-01-01",0.19524,{"date":308,"score":97,"percentile":309},"2026-01-02",0.19527,{"date":311,"score":97,"percentile":312},"2026-01-03",0.19504,{"date":314,"score":97,"percentile":283},"2026-01-04",{"date":316,"score":97,"percentile":300},"2026-01-05",{"date":318,"score":97,"percentile":319},"2026-01-06",0.19386,{"date":321,"score":97,"percentile":322},"2026-01-07",0.19417,{"date":324,"score":97,"percentile":325},"2026-01-08",0.19474,{"date":327,"score":97,"percentile":328},"2026-01-09",0.19473,{"date":330,"score":97,"percentile":331},"2026-01-10",0.19488,{"date":333,"score":97,"percentile":334},"2026-01-11",0.19455,{"date":336,"score":97,"percentile":322},"2026-01-12",{"date":338,"score":97,"percentile":339},"2026-01-13",0.19392,{"date":341,"score":97,"percentile":342},"2026-01-14",0.19452,{"date":344,"score":97,"percentile":345},"2026-01-15",0.19459,{"date":347,"score":97,"percentile":331},"2026-01-16",{"date":349,"score":97,"percentile":350},"2026-01-17",0.19501,{"date":352,"score":97,"percentile":353},"2026-01-18",0.19453,{"date":355,"score":97,"percentile":356},"2026-01-19",0.19407,{"date":358,"score":97,"percentile":339},"2026-01-20",{"date":360,"score":97,"percentile":361},"2026-01-21",0.1936,{"date":363,"score":97,"percentile":364},"2026-01-22",0.19302,{"date":366,"score":97,"percentile":367},"2026-01-23",0.19401,{"date":369,"score":97,"percentile":294},"2026-01-24",{"date":371,"score":97,"percentile":372},"2026-01-25",0.19354,{"date":374,"score":97,"percentile":375},"2026-01-26",0.19254,{"date":377,"score":97,"percentile":378},"2026-01-27",0.19244,{"date":380,"score":97,"percentile":257},"2026-01-28",{"date":382,"score":97,"percentile":383},"2026-01-29",0.19213,{"date":385,"score":97,"percentile":386},"2026-01-30",0.19224,{"date":388,"score":97,"percentile":389},"2026-01-31",0.19231,{"date":391,"score":97,"percentile":392},"2026-02-01",0.19256,[394,401],{"source":107,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":395,"cvss_v4_0":9},{"baseScore":396,"baseSeverity":397,"vectorString":398,"impactScore":399,"exploitabilityScore":400},3.3,"LOW","CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",2.3,4.6,{"source":101,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":402,"cvss_v4_0":9},{"baseScore":99,"baseSeverity":403,"vectorString":102,"impactScore":404,"exploitabilityScore":400},"HIGH",9.8,[406],{"ecosystem":9,"name":407,"vendor":408,"product":407,"cpe_part":409,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":410},"freeimage","freeimage_project","a",[411],{"version":412,"is_range":95,"range_type":413,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"3.18.0","cpe"]