VYPR
Vendor

Uclouvain

Products
1
CVEs
85
Across products
85
Status
Private

Products

1

Recent CVEs

85
View all 85 CVEs →
  • CVE-2017-17480CriDec 8, 2017
    risk 0.64cvss 9.8epss 0.05

    In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

  • CVE-2017-17479CriDec 8, 2017
    risk 0.64cvss 9.8epss 0.04

    In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

  • CVE-2017-14164HigSep 6, 2017
    risk 0.58cvss 8.8epss 0.05

    A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or…

  • CVE-2017-14152HigSep 5, 2017
    risk 0.58cvss 8.8epss 0.05

    A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in…

  • CVE-2017-14151HigSep 5, 2017
    risk 0.58cvss 8.8epss 0.05

    An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_mqc_flush in lib/openjp2/mqc.c…

  • CVE-2017-14041HigAug 30, 2017
    risk 0.58cvss 8.8epss 0.06

    A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

  • CVE-2017-14040HigAug 30, 2017
    risk 0.58cvss 8.8epss 0.05

    An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact.

  • CVE-2017-14039HigAug 30, 2017
    risk 0.58cvss 8.8epss 0.04

    A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.

  • CVE-2020-8112HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.04

    opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

  • CVE-2018-16376HigSep 3, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.

  • CVE-2018-16375HigSep 3, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.width in the function pnmtoimage in bin/jpwl/convert.c can lead to a heap-based buffer overflow.

  • CVE-2014-0158HigApr 10, 2018
    risk 0.57cvss 8.8epss 0.02

    Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file because of incorrect j2k_decode, j2k_read_eoc, and…

  • CVE-2015-8871CriSep 21, 2016
    risk 0.57cvss 9.8epss 0.03

    Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.

  • CVE-2021-3575HigMar 4, 2022
    risk 0.51cvss 7.8epss 0.02

    A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.

  • CVE-2020-27823HigMay 13, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

  • CVE-2020-27814HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.02

    A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

  • CVE-2020-27844HigJan 5, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality,…

  • CVE-2016-9675HigDec 22, 2016
    risk 0.51cvss 7.8epss 0.02

    openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.

  • CVE-2016-7163HigSep 21, 2016
    risk 0.51cvss 7.8epss 0.07

    Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.

  • CVE-2020-6851HigJan 13, 2020
    risk 0.49cvss 7.5epss 0.05

    OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.