cbcvebase.

Uclouvain Openjpeg vulnerabilities

83 known vulnerabilities affecting uclouvain/openjpeg.

Total CVEs
83
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH30MEDIUM43LOW1

Vulnerabilities

Page 1 of 5
CVE-2016-10504P3MEDIUMCVSS 6.5PoC≤ 2.1.22017-08-30
CVE-2016-10504 [MEDIUM] CWE-119 CVE-2016-10504: Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file.
nvd
CVE-2017-17480P3CRITICALCVSS 9.8v2.3.02017-12-08
CVE-2017-17480 [CRITICAL] CWE-787 CVE-2017-17480: In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/ In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
nvd
CVE-2017-17479P3CRITICALCVSS 9.8v2.3.02017-12-08
CVE-2017-17479 [CRITICAL] CWE-787 CVE-2017-17479: In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/c In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
nvd
CVE-2012-1499P3CRITICALCVSS 9.3≤ 1.4v1.32012-04-11
CVE-2012-1499 [CRITICAL] CWE-119 CVE-2012-1499: The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of a JPEG image, which triggers memory corruption, aka "out-of heap-based buffer write."
nvd
CVE-2013-4290P3CRITICALCVSS 10.0≤ 1.5.1v1.3+2 more2014-04-18
CVE-2013-4290 [CRITICAL] CWE-119 CVE-2013-4290: Stack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified imp Stack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified impact via unknown vectors to (1) lib/openjp3d/opj_jp3d_compress.c, (2) bin/jp3d/convert.c, or (3) lib/openjp3d/event.c.
nvd
CVE-2017-14164P3HIGHCVSS 8.8fixed in 2.3.02017-09-06
CVE-2017-14164 [HIGH] CVE-2017-14164: A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possibly remote code execution. NOTE: this vulnerability exists because of an incomplete
nvdosv
CVE-2017-14152P3HIGHCVSS 8.8v2.2.02017-09-05
CVE-2017-14152 [HIGH] CWE-787 CVE-2017-14152: A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJ A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c and opj_j2k_write_sot in lib/openjp2/j2k.c) or possibly remote code exec
nvd
CVE-2017-14151P3HIGHCVSS 8.8v2.2.02017-09-05
CVE-2017-14151 [HIGH] CWE-119 CVE-2017-14151: An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in O An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_mqc_flush in lib/openjp2/mqc.c and opj_t1_encode_cblk in lib/openjp2/t1.c) or possibly remote code execu
nvd
CVE-2017-14041P3HIGHCVSS 8.8v2.2.02017-08-30
CVE-2017-14041 [HIGH] CWE-787 CVE-2017-14041: A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in Open A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
nvd
CVE-2012-3358P3CRITICALCVSS 10.0v1.52012-07-18
CVE-2012-3358 [CRITICAL] CWE-119 CVE-2012-3358: Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow rem Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file.
nvd
CVE-2020-8112P3HIGHCVSS 8.8v2.3.12020-01-28
CVE-2020-8112 [HIGH] CVE-2020-8112: opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based b opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.
nvd
CVE-2025-54874P3CRITICALCVSS 9.8≤ 2.5.3v>= 2.5.1, <= 2.5.32025-08-05
CVE-2025-54874 [CRITICAL] CWE-457 CVE-2025-54874: OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_ OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
nvd
CVE-2015-8871P3CRITICALCVSS 9.8≤ 2.1.02016-09-21
CVE-2015-8871 [CRITICAL] CWE-416 CVE-2015-8871: Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 all Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.
nvd
CVE-2013-4289P3CRITICALCVSS 10.0≤ 1.5.1v1.3+2 more2014-04-18
CVE-2013-4289 [CRITICAL] CWE-189 CVE-2013-4289: Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigger a heap-based buffer overflow.
nvd
CVE-2016-7163P3HIGHCVSS 7.8fixed in 2.2.02016-09-21
CVE-2016-7163 [HIGH] CWE-190 CVE-2016-7163: Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.
nvd
CVE-2013-6045P3HIGHCVSS 7.5≤ 1.32013-12-12
CVE-2013-6045 [HIGH] CWE-119 CVE-2013-6045: Multiple heap-based buffer overflows in OpenJPEG 1.3 and earlier might allow remote attackers to exe Multiple heap-based buffer overflows in OpenJPEG 1.3 and earlier might allow remote attackers to execute arbitrary code via unspecified vectors.
nvdosv
CVE-2020-6851P3HIGHCVSS 7.5≤ 2.3.12020-01-13
CVE-2020-6851 [HIGH] CWE-787 CVE-2020-6851: OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
nvd
CVE-2017-14039P3HIGHCVSS 8.8fixed in 2.3.02017-08-30
CVE-2017-14039 [HIGH] CWE-787 CVE-2017-14039: A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.
nvd
CVE-2018-7648P3CRITICALCVSS 9.8v2.3.02018-03-02
CVE-2018-7648 [CRITICAL] CWE-119 CVE-2018-7648: An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checke An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line.
nvd
CVE-2018-16375P3HIGHCVSS 8.8v2.3.02018-09-03
CVE-2018-16375 [HIGH] CWE-787 CVE-2018-16375: An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.wid An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.width in the function pnmtoimage in bin/jpwl/convert.c can lead to a heap-based buffer overflow.
nvd