USC's vulnerability footprint centers on the Cereal serialization library, a narrowly scoped but integration-critical component embedded across C++ applications. The observed weakness classes—release of invalid pointers and use of uninitialized resources—reflect memory-safety challenges inherent to deserialization logic handling untrusted input. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Usc over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11105CRITICAL An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw pointer address as a unique identifier. This becomes problemat | Mar 30, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-11104MEDIUM An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable into a BinaryArchive or PortableBinaryArchive leaks several b | Mar 30, 2020 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Usc.
Media articles that mention a CVE ID that affects a product developed by Usc — matched by CVE ID, not by vendor name.