Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jasper project vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2017-6852
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote malicious users to have unspecified impact via a crafted image.
Jasper Project Jasper
4.3
CVSSv2
CVE-2016-8882
The jpc_dec_tilefini function in libjasper/jpc/jpc_dec.c in JasPer prior to 1.900.8 allows remote malicious users to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
Jasper Project Jasper
4.3
CVSSv2
CVE-2016-8883
The jpc_dec_tiledecode function in jpc_dec.c in JasPer prior to 1.900.8 allows remote malicious users to cause a denial of service (assertion failure) via a crafted file.
Jasper Project Jasper
4.3
CVSSv2
CVE-2016-8885
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer prior to 1.900.9 allows remote malicious users to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image.
Jasper Project Jasper
6.8
CVSSv2
CVE-2016-8886
The jas_malloc function in libjasper/base/jas_malloc.c in JasPer prior to 1.900.11 allows remote malicious users to have unspecified impact via a crafted file, which triggers a memory allocation failure.
Jasper Project Jasper
4.3
CVSSv2
CVE-2017-6851
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote malicious users to cause a denial of service (invalid read) via a crafted image.
Jasper Project Jasper
NA
CVE-2023-51257
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local malicious user to execute arbitrary code.
Jasper Project Jasper
7.5
CVSSv2
CVE-2014-9029
Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and previous versions allow remote malicious users to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.
Jasper Project Jasper
5
CVSSv2
CVE-2016-10248
The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer prior to 1.900.9 allows remote malicious users to cause a denial of service (NULL pointer dereference) via vectors involving an empty sequence.
Jasper Project Jasper
5
CVSSv2
CVE-2016-10250
The jp2_colr_destroy function in jp2_cod.c in JasPer prior to 1.900.13 allows remote malicious users to cause a denial of service (NULL pointer dereference) by leveraging incorrect cleanup of JP2 box data on error. NOTE: this vulnerability exists because of an incomplete fix for ...
Jasper Project Jasper
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-30924
CVE-2024-3400
overflow
CVE-2024-23528
CVE-2024-21338
CVE-2024-3818
CVE-2024-23535
NULL pointer dereference
elevation of privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »