Jpeg
Products
2- 13 CVEs
- 1 CVE
Recent CVEs
15| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-28026 | Hig | 0.51 | 7.8 | 0.01 | Mar 5, 2021 | jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicous jxl file using djxl, an attacker can trigger arbitrary code execution or a denial of service. | ||
| CVE-2022-37768 | Hig | 0.49 | 7.5 | 0.01 | Aug 18, 2022 | libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer. | ||
| CVE-2023-37837 | Med | 0.42 | 6.5 | 0.01 | Jul 13, 2023 | libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebitmaprequester.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | ||
| CVE-2023-37836 | Med | 0.42 | 6.5 | 0.01 | Jul 13, 2023 | libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | ||
| CVE-2022-37770 | Med | 0.42 | 6.5 | 0.01 | Aug 18, 2022 | libjpeg commit 281daa9 was discovered to contain a segmentation fault via LineMerger::GetNextLowpassLine at linemerger.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | ||
| CVE-2022-37769 | Med | 0.42 | 6.5 | 0.01 | Aug 18, 2022 | libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | ||
| CVE-2021-39520 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2021 | An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PushReconstructedData() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39519 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2021 | An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PullQData() located in blockbitmaprequester.cpp It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39518 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2021 | An issue was discovered in libjpeg through 2020021. LineBuffer::FetchRegion() in linebuffer.cpp has a heap-based buffer overflow. | ||
| CVE-2021-39517 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2021 | An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::ReconstructUnsampled() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39516 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2021 | An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function HuffmanDecoder::Get() located in huffmandecoder.hpp. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39515 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2021 | An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function SampleInterleavedLSScan::ParseMCU() located in sampleinterleavedlsscan.cpp. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39514 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2021 | An issue was discovered in libjpeg through 2020021. An uncaught floating point exception in the function ACLosslessScan::ParseMCU() located in aclosslessscan.cpp. It allows an attacker to cause Denial of Service. | ||
| CVE-2022-35166 | Med | 0.36 | 5.5 | 0.00 | Aug 18, 2022 | libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal. | ||
| CVE-2022-31796 | Med | 0.00 | 6.5 | 0.01 | Jun 2, 2022 | libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use. |
- risk 0.51cvss 7.8epss 0.01
jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicous jxl file using djxl, an attacker can trigger arbitrary code execution or a denial of service.
- risk 0.49cvss 7.5epss 0.01
libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
- risk 0.42cvss 6.5epss 0.01
libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebitmaprequester.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
- risk 0.42cvss 6.5epss 0.01
libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
- risk 0.42cvss 6.5epss 0.01
libjpeg commit 281daa9 was discovered to contain a segmentation fault via LineMerger::GetNextLowpassLine at linemerger.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
- risk 0.42cvss 6.5epss 0.01
libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PushReconstructedData() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PullQData() located in blockbitmaprequester.cpp It allows an attacker to cause Denial of Service.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in libjpeg through 2020021. LineBuffer::FetchRegion() in linebuffer.cpp has a heap-based buffer overflow.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::ReconstructUnsampled() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function HuffmanDecoder::Get() located in huffmandecoder.hpp. It allows an attacker to cause Denial of Service.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function SampleInterleavedLSScan::ParseMCU() located in sampleinterleavedlsscan.cpp. It allows an attacker to cause Denial of Service.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in libjpeg through 2020021. An uncaught floating point exception in the function ACLosslessScan::ParseMCU() located in aclosslessscan.cpp. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.00
libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.
- risk 0.00cvss 6.5epss 0.01
libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.