Mozilla Mozjpeg vulnerabilities
2 known vulnerabilities affecting mozilla/mozjpeg.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-13790HIGHCVSS 8.1v4.0.02020-06-03
CVE-2020-13790 [HIGH] CWE-125 CVE-2020-13790: libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.
libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.
nvd
CVE-2018-14498MEDIUMCVSS 6.5≤ 3.3.12019-03-07
CVE-2018-14498 [MEDIUM] CWE-125 CVE-2018-14498: get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers t
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
nvd