Ijg Libjpeg vulnerabilities

6 known vulnerabilities affecting ijg/libjpeg.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2020-14153HIGHCVSS 7.1≥ 8, ≤ 9c2020-06-15
CVE-2020-14153 [HIGH] CWE-125 CVE-2020-14153: In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for ce In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.
nvd
CVE-2020-14152HIGHCVSS 7.1fixed in 9d2020-06-15
CVE-2020-14152 [HIGH] CWE-400 CVE-2020-14152: In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.
nvd
CVE-2018-11813HIGHCVSS 7.5v9c2018-06-06
CVE-2018-11813 [HIGH] CWE-834 CVE-2018-11813: libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF. libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
nvd
CVE-2018-11212MEDIUMCVSS 6.5v9a2018-05-16
CVE-2018-11212 [MEDIUM] CWE-369 CVE-2018-11212: An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote a An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
nvd
CVE-2018-11213MEDIUMCVSS 6.5v9a2018-05-16
CVE-2018-11213 [MEDIUM] CVE-2018-11213: An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attac An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
nvd
CVE-2018-11214MEDIUMCVSS 6.5v9a2018-05-16
CVE-2018-11214 [MEDIUM] CVE-2018-11214: An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attack An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
nvd