VYPR

MozJPEG

by Mozilla Corporation

CVEs (2)

  • CVE-2018-14498MedMar 7, 2019
    risk 0.35cvss 6.5epss 0.03

    get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of…

  • CVE-2020-13790HigJun 3, 2020
    risk 0.00cvss 8.1epss 0.03

    libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.