4.3
CVSSv2

CVE-2016-10505

Published: 30/08/2017 Updated: 09/09/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG prior to 2.2.0 allow remote malicious users to cause a denial of service (application crash) via crafted j2k files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

uclouvain openjpeg

Vendor Advisories

NULL pointer dereference vulnerabilities in the imagetopnm function in convertc, sycc444_to_rgb function in colorc, color_esycc_to_rgb function in colorc, and sycc422_to_rgb function in colorc in OpenJPEG before 220 allow remote attackers to cause a denial of service (application crash) via crafted j2k files ...