cbcvebase.

Uclouvain Openjpeg vulnerabilities

83 known vulnerabilities affecting uclouvain/openjpeg.

Total CVEs
83
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH30MEDIUM43LOW1

Vulnerabilities

Page 4 of 5
CVE-2016-10505P4MEDIUMCVSS 6.5≤ 2.1.22017-08-30
CVE-2016-10505 [MEDIUM] CWE-476 CVE-2016-10505: NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb fun NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.
nvd
CVE-2020-27824P4MEDIUMCVSS 5.5fixed in 2.4.0vopenjpeg 2.4.02021-05-13
CVE-2020-27824 [MEDIUM] CWE-20 CVE-2020-27824: A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.
nvd
CVE-2016-10506P4MEDIUMCVSS 6.5≤ 2.1.22017-08-30
CVE-2016-10506 [MEDIUM] CWE-369 CVE-2016-10506: Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_nex Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.
nvd
CVE-2015-1239P4MEDIUMCVSS 6.5fixed in 2.1.12017-10-18
CVE-2015-1239 [MEDIUM] CWE-415 CVE-2015-1239: Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFiu Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.
nvd
CVE-2016-3183P4MEDIUMCVSS 5.5≤ 2.1.02017-02-03
CVE-2016-3183 [MEDIUM] CWE-125 CVE-2016-3183: The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cau The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.
nvd
CVE-2021-29338P4MEDIUMCVSS 5.5v2.4.02021-04-14
CVE-2021-29338 [MEDIUM] CWE-190 CVE-2021-29338: Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Deni Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.
nvd
CVE-2018-20845P4MEDIUMCVSS 6.5≤ 2.3.02019-06-26
CVE-2018-20845 [MEDIUM] CWE-369 CVE-2018-20845: Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in op Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
nvd
CVE-2018-20846P4MEDIUMCVSS 6.5≤ 2.3.02019-06-26
CVE-2018-20846 [MEDIUM] CWE-20 CVE-2018-20846: Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_n Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
nvd
CVE-2017-12982P4MEDIUMCVSS 5.5fixed in 2.3.02017-08-21
CVE-2017-12982 [MEDIUM] CWE-119 CVE-2017-12982: The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c.
nvd
CVE-2020-27845P4MEDIUMCVSS 5.5fixed in 2.4.0vopenjpeg 2.4.02021-01-05
CVE-2020-27845 [MEDIUM] CWE-125 CVE-2020-27845: There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is abl There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw is to application availability.
nvd
CVE-2020-27841P4MEDIUMCVSS 5.5fixed in 2.4.0vopenjpeg 2.4.02021-01-05
CVE-2020-27841 [MEDIUM] CWE-122 CVE-2020-27841: There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is a There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to application availability.
nvd
CVE-2013-6052P4MEDIUMCVSS 5.0≤ 1.32013-12-12
CVE-2013-6052 [MEDIUM] CWE-200 CVE-2013-6052: OpenJPEG 1.3 and earlier allows remote attackers to obtain sensitive information via unspecified vec OpenJPEG 1.3 and earlier allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read.
nvdosv
CVE-2013-6053P4MEDIUMCVSS 5.0v1.5.12014-04-27
CVE-2013-6053 [MEDIUM] CWE-20 CVE-2013-6053: OpenJPEG 1.5.1 allows remote attackers to obtain sensitive information via unspecified vectors that OpenJPEG 1.5.1 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read.
nvd
CVE-2020-27842P4MEDIUMCVSS 5.5fixed in 2.4.0vopenjpeg 2.4.02021-01-05
CVE-2020-27842 [MEDIUM] CWE-125 CVE-2020-27842: There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provi There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.
nvd
CVE-2013-1447P4MEDIUMCVSS 5.0≤ 1.32013-12-12
CVE-2013-1447 [MEDIUM] CVE-2013-1447: OpenJPEG 1.3 and earlier allows remote attackers to cause a denial of service (memory consumption or OpenJPEG 1.3 and earlier allows remote attackers to cause a denial of service (memory consumption or crash) via unspecified vectors related to NULL pointer dereferences, division-by-zero, and other errors.
nvdosv
CVE-2019-12973P4MEDIUMCVSS 5.5v2.3.12019-06-26
CVE-2019-12973 [MEDIUM] CVE-2019-12973: In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.
nvd
CVE-2022-1122P4MEDIUMCVSS 5.5v2.4.02022-03-29
CVE-2022-1122 [MEDIUM] CWE-665 CVE-2022-1122: A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input di A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
nvd
CVE-2018-6616P4MEDIUMCVSS 5.5v2.3.02018-02-04
CVE-2018-6616 [MEDIUM] CWE-400 CVE-2018-6616: In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
nvd
CVE-2016-3182P4MEDIUMCVSS 5.5fixed in 2.1.12020-02-20
CVE-2016-3182 [MEDIUM] CWE-119 CVE-2016-3182: The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to c The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
nvd
CVE-2023-39328P4MEDIUMCVSS 5.5v2.0v2.5.02024-07-09
CVE-2023-39328 [MEDIUM] CVE-2023-39328: A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypa A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file.
nvd
Uclouvain Openjpeg vulnerabilities | cvebase