VYPR

Jasper

by Jasper Project

Source repositories

CVEs (102)

  • CVE-2016-9600MedMar 12, 2018
    risk 0.42cvss 6.5epss 0.01

    JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash.

  • CVE-2017-14132MedSep 4, 2017
    risk 0.42cvss 6.5epss 0.02

    JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4,…

  • CVE-2016-10250HigMar 15, 2017
    risk 0.42cvss 7.5epss 0.04

    The jp2_colr_destroy function in jp2_cod.c in JasPer before 1.900.13 allows remote attackers to cause a denial of service (NULL pointer dereference) by leveraging incorrect cleanup of JP2 box data on error. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2016-10248HigMar 15, 2017
    risk 0.42cvss 7.5epss 0.04

    The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) via vectors involving an empty sequence.

  • CVE-2016-2089MedFeb 8, 2016
    risk 0.42cvss 6.5epss 0.03

    The jas_matrix_clip function in jas_seq.c in JasPer 1.900.1 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted JPEG 2000 image.

  • CVE-2016-1867MedJan 20, 2016
    risk 0.42cvss 6.5epss 0.02

    The jpc_pi_nextcprl function in JasPer 1.900.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.

  • CVE-2016-2116MedApr 13, 2016
    risk 0.37cvss 5.7epss 0.03

    Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.

  • CVE-2022-40755MedSep 16, 2022
    risk 0.36cvss 5.5epss 0.00

    JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.

  • CVE-2021-27845MedJul 15, 2021
    risk 0.36cvss 5.5epss 0.01

    A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c

  • CVE-2021-3467MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.01

    A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.

  • CVE-2021-3443MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.01

    A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.

  • CVE-2021-3272MedJan 27, 2021
    risk 0.36cvss 5.5epss 0.01

    jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.

  • CVE-2017-14232MedAug 15, 2019
    risk 0.36cvss 5.5epss 0.01

    The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted flif file.

  • CVE-2018-19139MedNov 9, 2018
    risk 0.36cvss 5.5epss 0.02

    An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.

  • CVE-2018-18873MedOct 31, 2018
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.

  • CVE-2018-9055MedMar 27, 2018
    risk 0.36cvss 5.5epss 0.02

    JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_firstone in libjasper/jpc/jpc_math.c.

  • CVE-2016-9591MedMar 9, 2018
    risk 0.36cvss 5.5epss 0.01

    JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.

  • CVE-2015-5203MedAug 2, 2017
    risk 0.36cvss 5.5epss 0.02

    Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

  • CVE-2017-9782MedJun 21, 2017
    risk 0.36cvss 5.5epss 0.02

    JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c.

  • CVE-2016-8884MedMar 28, 2017
    risk 0.36cvss 5.5epss 0.02

    The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for…

Page 3 of 6