VDB
CVE-2020-37121
CVE-2020-37121
PUBLISHED
CVSS 6.699999809265137 MEDIUM
CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious M3U playlist file with 536 bytes of buffer and shellcode to trigger remote code execution.
EPSS 0.20% · 9.6th percentile
Risk Scores
CVSS 4.0
6.699999809265137
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.20%
9.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | codeblocks | 0, 17.12+dfsg-1build1, 17.12+dfsg-1 |
| Ubuntu:25.10 | codeblocks | 25.03+dfsg-2, 0, 20.03+svn13046-0.4 |
| Ubuntu:24.04:LTS | codeblocks | 20.03+svn13046-0.2, 0, 20.03+svn13046-0.1build1 |
| Ubuntu:16.04:LTS | codeblocks | *, 0, 13.12-3.1build1 |
| Ubuntu:18.04:LTS | codeblocks | 16.01+dfsg-2.1, 0 |
| Ubuntu:22.04:LTS | codeblocks | 0, 20.03-3, 20.03-3.1 |
Timeline
- Feb 5, 2026 CVE Published
- Feb 6, 2026 EPSS Score
- Feb 8, 2026 EPSS Score
- Feb 11, 2026 EPSS Score
- Feb 12, 2026 CVE Updated
- Feb 13, 2026 EPSS Score
- Feb 15, 2026 EPSS Score
- Feb 17, 2026 EPSS Score
- Feb 20, 2026 EPSS Score
- Feb 22, 2026 EPSS Score
- Feb 24, 2026 EPSS Score
- Feb 26, 2026 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-37121 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-37121 third-party-advisory
- https://www.exploit-db.com/exploits/48344 third-party-advisory
- https://sourceforge.net/projects/codeblocks/ third-party-advisory
- https://www.codeblocks.org/ third-party-advisory
- https://www.vulncheck.com/advisories/codeblocks-buffer-overflow-seh-unicode third-party-advisory