Libjpeg Turbo
Source repositories
CVEs (37)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-35166 | Med | 0.36 | 5.5 | 0.00 | Aug 18, 2022 | libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal. | ||
| CVE-2019-13960 | Med | 0.36 | 5.5 | 0.01 | Jul 18, 2019 | In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and height values in the image header. NOTE: the vendor's expectation, for use cases in which this memory usage would be a denial of… | ||
| CVE-2014-9092 | Med | 0.36 | 6.5 | 0.04 | Oct 10, 2017 | libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker. | ||
| CVE-2026-75466 | Med | 0.35 | 6.5 | 0.00 | Aug 26, 2026 | libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a… | ||
| CVE-2018-14498 | Med | 0.35 | 6.5 | 0.04 | Mar 7, 2019 | get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of… | ||
| CVE-2013-6629 | 0.01 | — | 0.10 | Nov 19, 2013 | The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of… | |||
| CVE-2023-2804 | Med | 0.00 | 6.5 | 0.01 | May 25, 2023 | A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the sample data type exceeds the valid sample range,… | ||
| CVE-2020-35538 | Med | 0.00 | 5.5 | 0.00 | Aug 31, 2022 | A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo. | ||
| CVE-2021-46822 | Med | 0.00 | 5.5 | 0.01 | Jun 18, 2022 | The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in… | ||
| CVE-2022-32978 | Med | 0.00 | 6.5 | 0.01 | Jun 10, 2022 | There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan. | ||
| CVE-2022-32202 | Med | 0.00 | 5.5 | 0.01 | Jun 2, 2022 | In libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp. | ||
| CVE-2022-32201 | Med | 0.00 | 5.5 | 0.01 | Jun 2, 2022 | In libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp. | ||
| CVE-2022-31796 | Med | 0.00 | 6.5 | 0.01 | Jun 2, 2022 | libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use. | ||
| CVE-2022-31620 | Med | 0.00 | 6.5 | 0.01 | May 25, 2022 | In libjpeg before 1.64, BitStream::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-bounds array access during arithmetically coded lossless scan or arithmetically coded sequential scan. | ||
| CVE-2020-13790 | Hig | 0.00 | 8.1 | 0.03 | Jun 3, 2020 | libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file. | ||
| CVE-2018-1152 | Med | 0.00 | 6.5 | 0.04 | Jun 18, 2018 | libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image. | ||
| CVE-2013-6630 | 0.00 | — | 0.02 | Nov 19, 2013 | The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers,… |
- risk 0.36cvss 5.5epss 0.00
libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.
- risk 0.36cvss 5.5epss 0.01
In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and height values in the image header. NOTE: the vendor's expectation, for use cases in which this memory usage would be a denial of…
- risk 0.36cvss 6.5epss 0.04
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
- risk 0.35cvss 6.5epss 0.00
libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a…
- risk 0.35cvss 6.5epss 0.04
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of…
- CVE-2013-6629Nov 19, 2013risk 0.01cvss —epss 0.10
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of…
- risk 0.00cvss 6.5epss 0.01
A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the sample data type exceeds the valid sample range,…
- risk 0.00cvss 5.5epss 0.00
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
- risk 0.00cvss 5.5epss 0.01
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in…
- risk 0.00cvss 6.5epss 0.01
There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.
- risk 0.00cvss 5.5epss 0.01
In libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp.
- risk 0.00cvss 5.5epss 0.01
In libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp.
- risk 0.00cvss 6.5epss 0.01
libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.
- risk 0.00cvss 6.5epss 0.01
In libjpeg before 1.64, BitStream::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-bounds array access during arithmetically coded lossless scan or arithmetically coded sequential scan.
- risk 0.00cvss 8.1epss 0.03
libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.
- risk 0.00cvss 6.5epss 0.04
libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.
- CVE-2013-6630Nov 19, 2013risk 0.00cvss —epss 0.02
The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers,…
Page 2 of 2