VYPR

Openjpeg

by Uclouvain

Source repositories

CVEs (85)

  • CVE-2018-14423HigJul 19, 2018
    risk 0.49cvss 7.5epss 0.03

    Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).

  • CVE-2016-9114HigOct 30, 2016
    risk 0.49cvss 7.5epss 0.03

    There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.

  • CVE-2016-9113HigOct 30, 2016
    risk 0.49cvss 7.5epss 0.03

    There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.

  • CVE-2016-9112HigOct 29, 2016
    risk 0.49cvss 7.5epss 0.03

    Floating Point Exception (aka FPE or divide by zero) in opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.

  • CVE-2016-8332HigOct 28, 2016
    risk 0.49cvss 7.5epss 0.03

    A buffer overflow in OpenJPEG 2.1.1 causes arbitrary code execution when parsing a crafted image. An exploitable code execution vulnerability exists in the jpeg2000 image file format parser as implemented in the OpenJpeg library. A specially crafted jpeg2000 file can cause an…

  • CVE-2016-7445HigOct 3, 2016
    risk 0.49cvss 7.5epss 0.04

    convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.

  • CVE-2016-1924MedJan 27, 2016
    risk 0.43cvss 6.5epss 0.03

    The opj_tgt_reset function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.

  • CVE-2025-50952MedAug 7, 2025
    risk 0.42cvss 6.5epss 0.00

    openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

  • CVE-2023-39329MedJul 13, 2024
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.

  • CVE-2020-15389MedJun 29, 2020
    risk 0.42cvss 6.5epss 0.03

    jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy…

  • CVE-2019-6988MedJan 28, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.

  • CVE-2018-18088MedOct 9, 2018
    risk 0.42cvss 6.5epss 0.02

    OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c

  • CVE-2018-5785MedJan 19, 2018
    risk 0.42cvss 6.5epss 0.02

    In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.

  • CVE-2018-5727MedJan 16, 2018
    risk 0.42cvss 6.5epss 0.02

    In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.

  • CVE-2015-1239MedOct 18, 2017
    risk 0.42cvss 6.5epss 0.01

    Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.

  • CVE-2016-10505MedAug 30, 2017
    risk 0.42cvss 6.5epss 0.02

    NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service…

  • CVE-2016-9117MedOct 30, 2016
    risk 0.42cvss 6.5epss 0.02

    NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.

  • CVE-2016-9116MedOct 30, 2016
    risk 0.42cvss 6.5epss 0.02

    NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.

  • CVE-2016-9115MedOct 30, 2016
    risk 0.42cvss 6.5epss 0.02

    Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.

  • CVE-2016-1923MedJan 27, 2016
    risk 0.42cvss 6.5epss 0.02

    Heap-based buffer overflow in the opj_j2k_update_image_data function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.

Page 2 of 5