cbcvebase.

Debian Openjpeg2 vulnerabilities

64 known vulnerabilities affecting debian/openjpeg2.

Total CVEs
64
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH20MEDIUM27LOW15

Vulnerabilities

Page 1 of 4
CVE-2016-10504P3MEDIUMCVSS 6.5PoCfixed in openjpeg2 2.2.0-1 (bookworm)2016
CVE-2016-10504 [MEDIUM] CVE-2016-10504: openjpeg2 - Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.... Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file. Scope: local bookworm: resolved (fixed in 2.2.0-1) bullseye: resolved (fixed in 2.2.0-1) forky: resolved (fixed in 2.2.0-1) sid: resolved (fixed in 2.2.0-1) tri
debian
CVE-2017-17480P3CRITICALCVSS 9.8fixed in openjpeg2 2.3.0-2 (bookworm)2017
CVE-2017-17480 [CRITICAL] CVE-2017-17480: openjpeg2 - In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolu... In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution. Scope: local bookworm: resolved (fixed in 2.3.0-2) bullseye: resolved (fixed in 2.3.0-2) forky: resolved (fixed in 2.3.0-2)
debian
CVE-2017-17479P3LOWCVSS 9.8fixed in openjpeg2 2.3.0-2 (bookworm)2017
CVE-2017-17479 [CRITICAL] CVE-2017-17479: openjpeg2 - In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimag... In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution. Scope: local bookworm: resolved (fixed in 2.3.0-2) bullseye: resolved (fixed in 2.3.0-2) forky: resolved (fixed in 2.3.0-2) s
debian
CVE-2017-14152P3HIGHCVSS 8.8fixed in openjpeg2 2.3.0-1 (bookworm)2017
CVE-2017-14152 [HIGH] CVE-2017-14152: openjpeg2 - A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/op... A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c and opj_j2k_write_sot in lib/openjp2/j2k.c) or possibly remote code execution. Scope:
debian
CVE-2016-5157P3HIGHCVSS 8.8fixed in openjpeg2 2.1.2-1 (bookworm)2016
CVE-2016-5157 [HIGH] CVE-2016-5157: openjpeg2 - Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in Open... Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data. Scope: local bookworm: resolved (fixed in 2.1.2-1) bullseye: resolved (fix
debian
CVE-2017-14151P3HIGHCVSS 8.8fixed in openjpeg2 2.3.0-1 (bookworm)2017
CVE-2017-14151 [HIGH] CVE-2017-14151: openjpeg2 - An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in li... An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_mqc_flush in lib/openjp2/mqc.c and opj_t1_encode_cblk in lib/openjp2/t1.c) or possibly remote code execution. Scope:
debian
CVE-2017-14041P3HIGHCVSS 8.8fixed in openjpeg2 2.3.0-1 (bookworm)2017
CVE-2017-14041 [HIGH] CVE-2017-14041: openjpeg2 - A stack-based buffer overflow was discovered in the pgxtoimage function in bin/j... A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution. Scope: local bookworm: resolved (fixed in 2.3.0-1) bullseye: resolved (fixed in 2.3.0-1) forky: resolved (fixed in 2.3.0-1) sid
debian
CVE-2020-8112P3HIGHCVSS 7.5fixed in openjpeg2 2.4.0-1 (bookworm)2020
CVE-2020-8112 [HIGH] CVE-2020-8112: openjpeg2 - opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-2... opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky: resolved (fixed in 2.4.0-1) sid: resolved (fixed in 2.4.0-1) trixie: resolved (fixed in 2.4.0-1)
debian
CVE-2015-8871P3CRITICALCVSS 9.8fixed in openjpeg2 2.1.1-1 (bookworm)2015
CVE-2015-8871 [CRITICAL] CVE-2015-8871: openjpeg2 - Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJ... Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors. Scope: local bookworm: resolved (fixed in 2.1.1-1) bullseye: resolved (fixed in 2.1.1-1) forky: resolved (fixed in 2.1.1-1) sid: resolved (fixed in 2.1.1-1) trixie: resolved (fixed in 2.1.1-1)
debian
CVE-2025-54874P3LOWCVSS 6.6fixed in openjpeg2 2.5.3-2.1 (forky)2025
CVE-2025-54874 [MEDIUM] CVE-2025-54874: openjpeg2 - OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3... OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 2.5.3-2.1) sid: resolved (fixed in 2.5.3-2.1) trixie: resolved (fi
debian
CVE-2016-7163P3HIGHCVSS 7.8fixed in openjpeg2 2.1.2-1 (bookworm)2016
CVE-2016-7163 [HIGH] CVE-2016-7163: openjpeg2 - Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows... Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write. Scope: local bookworm: resolved (fixed in 2.1.2-1) bullseye: resolved (fixed in 2.1.2-1) forky: resolved (fixed in 2.1.2-1) sid: resolved (fixed in 2.1.2-1) trixie: resolved
debian
CVE-2020-6851P3HIGHCVSS 7.5fixed in openjpeg2 2.4.0-1 (bookworm)2020
CVE-2020-6851 [HIGH] CVE-2020-6851: openjpeg2 - OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_pr... OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky: resolved (fixed in 2.4.0-1) sid: resolved (fixed in 2.4.0-1) trixie: resolved (fixed in 2.4.0-1)
debian
CVE-2017-14039P3HIGHCVSS 8.8fixed in openjpeg2 2.3.0-1 (bookworm)2017
CVE-2017-14039 [HIGH] CVE-2017-14039: openjpeg2 - A heap-based buffer overflow was discovered in the opj_t2_encode_packet function... A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact. Scope: local bookworm: resolved (fixed in 2.3.0-1) bullseye: resolved (fixed in 2.3.0-1) forky: resolved (fixed in 2
debian
CVE-2018-7648P3LOWCVSS 9.8fixed in openjpeg2 2.3.1-1 (bookworm)2018
CVE-2018-7648 [CRITICAL] CVE-2018-7648: openjpeg2 - An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output p... An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line. Scope: local bookworm: resolved (fixed in 2.3.1-1) bullseye: resolved (fixed in 2.3.1-1) forky: resolved (fixed in 2.3.1-1) sid: resolved (fixed in
debian
CVE-2018-16375P3LOWCVSS 8.8fixed in openjpeg2 2.3.1-1 (bookworm)2018
CVE-2018-16375 [HIGH] CVE-2018-16375: openjpeg2 - An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height... An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.width in the function pnmtoimage in bin/jpwl/convert.c can lead to a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 2.3.1-1) bullseye: resolved (fixed in 2.3.1-1) forky: resolved (fixed in 2.3.1-1) sid: resolved (fixed in 2.3.1-1) trixie: resolve
debian
CVE-2018-21010P3HIGHCVSS 8.8fixed in openjpeg2 2.3.1-1 (bookworm)2018
CVE-2018-21010 [HIGH] CVE-2018-21010: openjpeg2 - OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in b... OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c. Scope: local bookworm: resolved (fixed in 2.3.1-1) bullseye: resolved (fixed in 2.3.1-1) forky: resolved (fixed in 2.3.1-1) sid: resolved (fixed in 2.3.1-1) trixie: resolved (fixed in 2.3.1-1)
debian
CVE-2018-20847P3LOWCVSS 8.8fixed in openjpeg2 2.3.1-1 (bookworm)2018
CVE-2018-20847 [HIGH] CVE-2018-20847: openjpeg2 - An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get... An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow. Scope: local bookworm: resolved (fixed in 2.3.1-1) bullseye: resolved (fixed in 2.3.1-1) forky: resolved (fixed in 2.3.1-1) sid: resolved (fixed in 2.3.1-1) trixie: resolved (fixed in 2.3.1-
debian
CVE-2016-5159P3HIGHCVSS 8.8fixed in openjpeg2 2.1.2-1 (bookworm)2016
CVE-2016-5159 [HIGH] CVE-2016-5159: openjpeg2 - Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome befor... Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during opj_aligned_malloc calls in dwt.c and t1.c.
debian
CVE-2017-14040P3HIGHCVSS 8.8fixed in openjpeg2 2.3.0-1 (bookworm)2017
CVE-2017-14040 [HIGH] CVE-2017-14040: openjpeg2 - An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, t... An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact. Scope: local bookworm: resolved (fixed in 2.3.0-1) bullseye: resolved (fixed in 2.3.0-1) forky: resolved (fixed in 2.3.0-1) sid: resolved (fixed in
debian
CVE-2016-5152P3HIGHCVSS 8.8fixed in openjpeg2 2.1.2-1.2 (bookworm)2016
CVE-2016-5152 [HIGH] CVE-2016-5152: openjpeg2 - Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJ... Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data. Scope: local bookworm:
debian
Debian Openjpeg2 vulnerabilities | cvebase