Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown
CVE-2020-8175
Disclosure Date: July 24, 2020 (last updated February 21, 2025)
Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.
0
Attacker Value
Unknown
CVE-2020-13790
Disclosure Date: June 03, 2020 (last updated February 21, 2025)
libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.
0
Attacker Value
Unknown
CVE-2019-13960
Disclosure Date: July 18, 2019 (last updated November 08, 2023)
In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and height values in the image header. NOTE: the vendor's expectation, for use cases in which this memory usage would be a denial of service, is that the application should interpret libjpeg warnings as fatal errors (aborting decompression) and/or set limits on resource consumption or image sizes
0
Attacker Value
Unknown
CVE-2018-14498
Disclosure Date: March 07, 2019 (last updated November 08, 2023)
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
0
Attacker Value
Unknown
CVE-2018-20330
Disclosure Date: December 21, 2018 (last updated November 27, 2024)
The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.
0
Attacker Value
Unknown
CVE-2018-19664
Disclosure Date: November 29, 2018 (last updated November 27, 2024)
libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.
0
Attacker Value
Unknown
CVE-2018-14944
Disclosure Date: August 05, 2018 (last updated November 27, 2024)
An issue has been found in jpeg_encoder through 2015-11-27. It is a SEGV in the function readFromBMP in jpeg_encoder.cpp. The signal is caused by an out-of-bounds write.
0
Attacker Value
Unknown
CVE-2018-14945
Disclosure Date: August 05, 2018 (last updated November 27, 2024)
An issue has been found in jpeg_encoder through 2015-11-27. It is a heap-based buffer overflow in the function readFromBMP in jpeg_encoder.cpp.
0
Attacker Value
Unknown
CVE-2018-13037
Disclosure Date: July 01, 2018 (last updated November 26, 2024)
An issue was discovered in jpeg-compressor 0.1. The bmp_load function in stb_image.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact.
0
Attacker Value
Unknown
CVE-2018-13030
Disclosure Date: June 30, 2018 (last updated November 26, 2024)
An issue was discovered in jpeg-compressor 0.1. The build_huffman function in stb_image.c allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact.
0