Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jasper vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-4769
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote malicious users to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) r...
Jasper Httpdx 1.4.6b
Jasper Httpdx 1.4
Jasper Httpdx 1.4.5
Jasper Httpdx 1.4.6
Jasper Httpdx 1.5
2 EDB exploits
NA
CVE-2009-4770
The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makes it easier for remote malicious users to obtain privileged access.
Jasper Httpdx 1.5
Jasper Httpdx 1.4
Jasper Httpdx 1.4.5
Jasper Httpdx 1.4.6
Jasper Httpdx 1.4.6b
NA
CVE-2009-4531
httpdx 1.4.4 and previous versions allows remote malicious users to obtain the source code for a web page by appending a . (dot) character to the URI.
Jasper Httpdx 1.4.3
Jasper Httpdx
Jasper Httpdx 1.4
1 EDB exploit
5.5
CVSSv3
CVE-2017-6851
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote malicious users to cause a denial of service (invalid read) via a crafted image.
Jasper Project Jasper
7.5
CVSSv3
CVE-2016-10248
The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer prior to 1.900.9 allows remote malicious users to cause a denial of service (NULL pointer dereference) via vectors involving an empty sequence.
Jasper Project Jasper
7.5
CVSSv3
CVE-2016-10250
The jp2_colr_destroy function in jp2_cod.c in JasPer prior to 1.900.13 allows remote malicious users to cause a denial of service (NULL pointer dereference) by leveraging incorrect cleanup of JP2 box data on error. NOTE: this vulnerability exists because of an incomplete fix for ...
Jasper Project Jasper
8.8
CVSSv3
CVE-2015-8751
Integer overflow in the jas_matrix_create function in JasPer allows context-dependent malicious users to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.
Jasper Project Jasper
NA
CVE-2014-9029
Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and previous versions allow remote malicious users to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.
Jasper Project Jasper
5.5
CVSSv3
CVE-2021-27845
A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c
Jasper Project Jasper
7.8
CVSSv3
CVE-2017-6852
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote malicious users to have unspecified impact via a crafted image.
Jasper Project Jasper
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »