Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jasper vulnerabilities and exploits
(subscribe to this query)
9.3
CVSSv2
CVE-2009-4769
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote malicious users to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) r...
Jasper Httpdx 1.4.6b
Jasper Httpdx 1.4
Jasper Httpdx 1.4.5
Jasper Httpdx 1.4.6
Jasper Httpdx 1.5
2 EDB exploits
7.5
CVSSv2
CVE-2009-4770
The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makes it easier for remote malicious users to obtain privileged access.
Jasper Httpdx 1.5
Jasper Httpdx 1.4
Jasper Httpdx 1.4.5
Jasper Httpdx 1.4.6
Jasper Httpdx 1.4.6b
5
CVSSv2
CVE-2009-4531
httpdx 1.4.4 and previous versions allows remote malicious users to obtain the source code for a web page by appending a . (dot) character to the URI.
Jasper Httpdx 1.4.3
Jasper Httpdx
Jasper Httpdx 1.4
1 EDB exploit
NA
CVE-2023-51257
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local malicious user to execute arbitrary code.
Jasper Project Jasper
5
CVSSv2
CVE-2016-10250
The jp2_colr_destroy function in jp2_cod.c in JasPer prior to 1.900.13 allows remote malicious users to cause a denial of service (NULL pointer dereference) by leveraging incorrect cleanup of JP2 box data on error. NOTE: this vulnerability exists because of an incomplete fix for ...
Jasper Project Jasper
6.8
CVSSv2
CVE-2015-8751
Integer overflow in the jas_matrix_create function in JasPer allows context-dependent malicious users to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.
Jasper Project Jasper
6.8
CVSSv2
CVE-2017-6852
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote malicious users to have unspecified impact via a crafted image.
Jasper Project Jasper
4.3
CVSSv2
CVE-2017-6851
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote malicious users to cause a denial of service (invalid read) via a crafted image.
Jasper Project Jasper
4.3
CVSSv2
CVE-2021-27845
A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c
Jasper Project Jasper
4.3
CVSSv2
CVE-2016-8882
The jpc_dec_tilefini function in libjasper/jpc/jpc_dec.c in JasPer prior to 1.900.8 allows remote malicious users to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
Jasper Project Jasper
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-21987
buffer overflow
CVE-2024-28890
CVE-2024-27574
CVE-2024-27347
CVE-2024-31450
privilege
SSTI
CVE-2024-31666
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »