cbcvebase.
CVE-2016-8654
published 2018-08-01

CVE-2016-8654: A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are…

PriorityP336high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.91%
77.6th percentile
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
jasper_projectjasper< 2.0.02.0.0
jasper_projectjasper>= 0 < 1.900.1-14ubuntu3.41.900.1-14ubuntu3.4
jasper_projectjasper>= 0 < 1.900.1-debian1-2.4ubuntu1.11.900.1-debian1-2.4ubuntu1.1
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
the_jasper_projectjasper

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.