CVE-2015-6776
published 2015-12-06CVE-2015-6776: The opj_dwt_decode_1* functions in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 47.0.2526.73, allow remote attackers to cause a denial of…
PriorityP426medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.46%
71.0th percentile
The opj_dwt_decode_1* functions in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 47.0.2526.73, allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during a discrete wavelet transform.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| datatables | datatables | >= 0 < 1.10.10 | 1.10.10 |
| chrome | <= 46.0.2490.86 | — | |
| sprymedia | datatables | >= 0 < 1.10.10 | 1.10.10 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2ggh-34r5-2jc7: The opj_dwt_decode_1* functions in dwt
ghsa_unreviewed·2022-05-17
CVE-2015-6776 [MEDIUM] CWE-119 GHSA-2ggh-34r5-2jc7: The opj_dwt_decode_1* functions in dwt
The opj_dwt_decode_1* functions in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 47.0.2526.73, allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during a discrete wavelet transform.
GHSA
DataTable Vulnerable to Cross-Site Scripting
ghsa·2020-08-31
CVE-2015-6584 [HIGH] CWE-79 DataTable Vulnerable to Cross-Site Scripting
DataTable Vulnerable to Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.
## Recommendation
Update to a version greater than 1.10.8. A [fix](https://github.com/DataTables/DataTablesSrc/commit/ccf86dc5982bd8e16d) appears in [version 1.10.10](https://github.com/DataTables/DataTablesSrc/commits/1.10.10?after=9780a3693572757d87bf70e48bd7555faf974f28+34&branch=1.10.10&qualified_name=refs%2Ftags%2F1.10.10).
OSV
CVE-2015-6776: The opj_dwt_decode_1* functions in dwt
osv·2015-12-06·CVSS 6.8
CVE-2015-6776 [MEDIUM] CVE-2015-6776: The opj_dwt_decode_1* functions in dwt
The opj_dwt_decode_1* functions in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 47.0.2526.73, allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during a discrete wavelet transform.
Red Hat
chromium-browser: Out of bounds access in PDFium
vendor_redhat·2015-12-01·CVSS 6.8
CVE-2015-6776 [MEDIUM] CWE-119 chromium-browser: Out of bounds access in PDFium
chromium-browser: Out of bounds access in PDFium
The opj_dwt_decode_1* functions in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 47.0.2526.73, allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during a discrete wavelet transform.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00017.htmlhttp://www.debian.org/security/2015/dsa-3415http://www.securityfocus.com/bid/78416http://www.securitytracker.com/id/1034298https://code.google.com/p/chromium/issues/detail?id=457480https://codereview.chromium.org/1416783002https://codereview.chromium.org/1416783002/diff/20001/third_party/libopenjpeg20/0003-dwt-decode.patchhttps://codereview.chromium.org/1416783002/diff/20001/third_party/libopenjpeg20/README.pdfiumhttps://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00017.htmlhttp://www.debian.org/security/2015/dsa-3415http://www.securityfocus.com/bid/78416http://www.securitytracker.com/id/1034298https://code.google.com/p/chromium/issues/detail?id=457480https://codereview.chromium.org/1416783002https://codereview.chromium.org/1416783002/diff/20001/third_party/libopenjpeg20/0003-dwt-decode.patchhttps://codereview.chromium.org/1416783002/diff/20001/third_party/libopenjpeg20/README.pdfiumhttps://security.gentoo.org/glsa/201603-09
2015-12-06
Published