VYPR

Jasper

by Mdadams

Source repositories

CVEs (24)

  • CVE-2016-9387HigMar 23, 2017
    risk 0.51cvss 7.8epss 0.00

    Integer overflow in the jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.13 allows remote attackers to have unspecified impact via a crafted file, which triggers an assertion failure.

  • CVE-2016-9560HigFeb 15, 2017
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have unspecified impact via a crafted image.

  • CVE-2017-14229HigSep 9, 2017
    risk 0.49cvss 7.5epss 0.01

    There is an infinite loop in the jpc_dec_tileinit function in jpc/jpc_dec.c of Jasper 2.0.13. It will lead to a remote denial of service attack.

  • CVE-2017-13746HigAug 29, 2017
    risk 0.49cvss 7.5epss 0.02

    There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack.

  • CVE-2017-1000050HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.02

    JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.

  • CVE-2016-9391HigMar 23, 2017
    risk 0.49cvss 7.5epss 0.01

    The jpc_bitstream_getbits function in jpc_bs.c in JasPer before 2.0.10 allows remote attackers to cause a denial of service (assertion failure) via a very large integer.

  • CVE-2016-9389HigMar 23, 2017
    risk 0.49cvss 7.5epss 0.02

    The jpc_irct and jpc_iict functions in jpc_mct.c in JasPer before 1.900.14 allow remote attackers to cause a denial of service (assertion failure).

  • CVE-2016-10248HigMar 15, 2017
    risk 0.49cvss 7.5epss 0.01

    The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) via vectors involving an empty sequence.

  • CVE-2015-5203MedAug 2, 2017
    risk 0.36cvss 5.5epss 0.01

    Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

  • CVE-2017-9782MedJun 21, 2017
    risk 0.36cvss 5.5epss 0.00

    JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c.

  • CVE-2016-8884MedMar 28, 2017
    risk 0.36cvss 5.5epss 0.00

    The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2016-9557MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file.

  • CVE-2016-9392MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    The calcstepsizes function in jpc_dec.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.

  • CVE-2016-9390MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.

  • CVE-2016-9388MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.

  • CVE-2016-9262MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

  • CVE-2017-6851MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.

  • CVE-2017-6850MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.

  • CVE-2016-8692MedFeb 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP image to the imginfo command.

  • CVE-2016-8691MedFeb 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo command.

Page 1 of 2