cbcvebase.

Uclouvain Openjpeg vulnerabilities

83 known vulnerabilities affecting uclouvain/openjpeg.

Total CVEs
83
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH30MEDIUM43LOW1

Vulnerabilities

Page 3 of 5
CVE-2016-7445P4HIGHCVSS 7.5≤ 2.1.12016-10-03
CVE-2016-7445 [HIGH] CWE-476 CVE-2016-7445: convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointe convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.
nvdosv
CVE-2020-15389P4MEDIUMCVSS 6.5≤ 2.3.12020-06-29
CVE-2020-15389 [MEDIUM] CWE-416 CVE-2020-15389: jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there i jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
nvd
CVE-2018-14423P4HIGHCVSS 7.5≤ 2.3.02018-07-19
CVE-2018-14423 [HIGH] CWE-369 CVE-2018-14423: Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in li Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
nvd
CVE-2025-50952P4MEDIUMCVSS 6.5v2.5.02025-08-07
CVE-2025-50952 [MEDIUM] CWE-476 CVE-2025-50952: openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
nvd
CVE-2016-9118P4MEDIUMCVSS 5.3v2.1.22016-10-30
CVE-2016-9118 [MEDIUM] CWE-119 CVE-2016-9118: Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2. Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
nvd
CVE-2016-1923P4MEDIUMCVSS 6.5v2.1.02016-01-27
CVE-2016-1923 [MEDIUM] CWE-119 CVE-2016-1923: Heap-based buffer overflow in the opj_j2k_update_image_data function in OpenJpeg 2016.1.18 allows re Heap-based buffer overflow in the opj_j2k_update_image_data function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.
nvd
CVE-2016-9572P4MEDIUMCVSS 6.5v2.1.22018-08-01
CVE-2016-9572 [MEDIUM] CWE-476 CVE-2016-9572: A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Du A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
nvd
CVE-2023-39329P4MEDIUMCVSS 6.5v2.0v2.5.02024-07-13
CVE-2023-39329 [MEDIUM] CWE-400 CVE-2023-39329: A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.
nvd
CVE-2016-1924P4MEDIUMCVSS 6.5≤ 2.1.02016-01-27
CVE-2016-1924 [MEDIUM] CWE-119 CVE-2016-1924: The opj_tgt_reset function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of servic The opj_tgt_reset function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.
nvd
CVE-2016-9116P4MEDIUMCVSS 6.5v2.1.22016-10-30
CVE-2016-9116 [MEDIUM] CWE-476 CVE-2016-9116: NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denia NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
nvd
CVE-2016-9117P4MEDIUMCVSS 6.5v2.1.22016-10-30
CVE-2016-9117 [MEDIUM] CWE-476 CVE-2016-9117: NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denia NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
nvd
CVE-2016-9115P4MEDIUMCVSS 6.5v2.1.22016-10-30
CVE-2016-9115 [MEDIUM] CWE-119 CVE-2016-9115: Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Deni Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
nvd
CVE-2016-10507P4MEDIUMCVSS 6.5≤ 2.1.22017-08-30
CVE-2016-10507 [MEDIUM] CWE-190 CVE-2016-10507: Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file.
nvd
CVE-2013-6887P4MEDIUMCVSS 6.4v1.5.12014-04-27
CVE-2013-6887 [MEDIUM] CWE-20 CVE-2013-6887: OpenJPEG 1.5.1 allows remote attackers to cause a denial of service via unspecified vectors that tri OpenJPEG 1.5.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger NULL pointer dereferences, division-by-zero, and other errors.
nvd
CVE-2016-4796P4MEDIUMCVSS 5.5≤ 2.1.02017-02-03
CVE-2016-4796 [MEDIUM] CWE-119 CVE-2016-4796: Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allow Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.
nvd
CVE-2018-5785P4MEDIUMCVSS 6.5v2.3.02018-01-19
CVE-2018-5785 [MEDIUM] CWE-190 CVE-2018-5785: In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
nvd
CVE-2018-18088P4MEDIUMCVSS 6.5v2.3.02018-10-09
CVE-2018-18088 [MEDIUM] CWE-476 CVE-2018-18088: OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c
nvd
CVE-2018-5727P4MEDIUMCVSS 6.5v2.3.02018-01-16
CVE-2018-5727 [MEDIUM] CWE-190 CVE-2018-5727: In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (o In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
nvd
CVE-2019-6988P4MEDIUMCVSS 6.5v2.3.02019-01-28
CVE-2019-6988 [MEDIUM] CWE-770 CVE-2019-6988: An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service ( An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.
nvd
CVE-2020-27843P4MEDIUMCVSS 5.5fixed in 2.4.0vopenjpeg 2.4.02021-01-05
CVE-2020-27843 [MEDIUM] CWE-125 CVE-2020-27843: A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide spe A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system availability.
nvd
Uclouvain Openjpeg vulnerabilities | cvebase