Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jasper vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2009-4770
The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makes it easier for remote malicious users to obtain privileged access.
Jasper Httpdx 1.5
Jasper Httpdx 1.4
Jasper Httpdx 1.4.5
Jasper Httpdx 1.4.6
Jasper Httpdx 1.4.6b
9.3
CVSSv2
CVE-2009-4769
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote malicious users to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) r...
Jasper Httpdx 1.4.6b
Jasper Httpdx 1.4
Jasper Httpdx 1.4.5
Jasper Httpdx 1.4.6
Jasper Httpdx 1.5
2 EDB exploits
5
CVSSv2
CVE-2009-4531
httpdx 1.4.4 and previous versions allows remote malicious users to obtain the source code for a web page by appending a . (dot) character to the URI.
Jasper Httpdx 1.4.3
Jasper Httpdx
Jasper Httpdx 1.4
1 EDB exploit
NA
CVE-2023-51257
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local malicious user to execute arbitrary code.
Jasper Project Jasper
1 Github repository
4.3
CVSSv2
CVE-2016-8885
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer prior to 1.900.9 allows remote malicious users to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image.
Jasper Project Jasper
6.8
CVSSv2
CVE-2016-8886
The jas_malloc function in libjasper/base/jas_malloc.c in JasPer prior to 1.900.11 allows remote malicious users to have unspecified impact via a crafted file, which triggers a memory allocation failure.
Jasper Project Jasper
4.3
CVSSv2
CVE-2016-8882
The jpc_dec_tilefini function in libjasper/jpc/jpc_dec.c in JasPer prior to 1.900.8 allows remote malicious users to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
Jasper Project Jasper
4.3
CVSSv2
CVE-2016-8883
The jpc_dec_tiledecode function in jpc_dec.c in JasPer prior to 1.900.8 allows remote malicious users to cause a denial of service (assertion failure) via a crafted file.
Jasper Project Jasper
6.8
CVSSv2
CVE-2015-8751
Integer overflow in the jas_matrix_create function in JasPer allows context-dependent malicious users to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.
Jasper Project Jasper
7.5
CVSSv2
CVE-2014-9029
Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and previous versions allow remote malicious users to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.
Jasper Project Jasper
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
bypass
open redirect
CVE-2024-4358
CVE-2024-24199
CVE-2024-5550
CVE-2024-5305
CVE-2024-30373
CVE-2024-1800
deserialization
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »