Show filters
77 Total Results
Displaying 11-20 of 77
Sort by:
Attacker Value
Unknown
CVE-2020-27844
Disclosure Date: January 05, 2021 (last updated November 08, 2023)
A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
0
Attacker Value
Unknown
CVE-2020-15389
Disclosure Date: June 29, 2020 (last updated November 28, 2024)
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
0
Attacker Value
Unknown
CVE-2016-3182
Disclosure Date: February 20, 2020 (last updated February 21, 2025)
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
0
Attacker Value
Unknown
CVE-2020-8112
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.
0
Attacker Value
Unknown
CVE-2020-6851
Disclosure Date: January 13, 2020 (last updated February 21, 2025)
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
0
Attacker Value
Unknown
CVE-2018-21010
Disclosure Date: September 05, 2019 (last updated November 27, 2024)
OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.
0
Attacker Value
Unknown
CVE-2018-20847
Disclosure Date: June 26, 2019 (last updated November 27, 2024)
An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.
0
Attacker Value
Unknown
CVE-2019-12973
Disclosure Date: June 26, 2019 (last updated November 27, 2024)
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.
0
Attacker Value
Unknown
CVE-2018-20845
Disclosure Date: June 26, 2019 (last updated November 27, 2024)
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
0
Attacker Value
Unknown
CVE-2018-20846
Disclosure Date: June 26, 2019 (last updated November 27, 2024)
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
0