A vulnerability classified as problematic has been found in MediaArea ZenLib up to 0.4.38. This affects the function Ztring::Date_From_Seconds_1970_Local of the file Source/ZenLib/Ztring.cpp. The manipulation of the argument Value leads to unchecked return value to null pointer dereference. Upgrading to version 0.4.39 is able to address this issue. The identifier of the patch is 6475fcccd37c9cf17e0cfe263b5fe0e2e47a8408. It is recommended to upgrade the affected component. The identifier VDB-217629 was assigned to this vulnerability.
Conclusion & alert: CVE-2020-36646 is rated Moderate Risk (46.5/100): CVSS Low severity, with medium exploitation likelihood (EPSS 2.58%). Core evidence: EPSS rose +2.48% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-03 | 0.10% | 2.58% | +2.48% |
| 2 | 2025-11-21 | 1.50% | 0.10% | -1.41% |
| 3 | 2025-11-18 | — | 1.50% | — |
Full EPSS history (19 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 3.5 | 3.1 | LOW |
|
2.1 | 1.4 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 2.3 | 2.0 | LOW |
|
4.4 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2020-36646 not yet assigned priority: Debian including 1 source packages (libzen), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-36646 |
ubuntu
|
medium | CVE-2020-36646 medium priority: Ubuntu including 1 source packages (libzen), 8 status rows across 8 suites (bionic, focal, jammy, kinetic, lunar, trusty, upstream, xenial): released 5, not-affected 3. | https://ubuntu.com/security/CVE-2020-36646 |
| URL | Tags |
|---|---|
| https://github.com/MediaArea/ZenLib/commit/6475fcccd37c9cf17e0cfe263b5fe0e2e47a8408 | Patch |
| https://github.com/MediaArea/ZenLib/pull/119 | Patch |
| https://github.com/MediaArea/ZenLib/releases/tag/v0.4.39 | Release Notes |
| https://vuldb.com/?ctiid.217629 | Third Party Advisory VDB Entry |
| https://vuldb.com/?id.217629 | Third Party Advisory VDB Entry |