Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2023-6562

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a specially-crafted the image that is displayed back to the attacker.
Attacker Value
Unknown

CVE-2019-5144

Disclosure Date: December 12, 2019 (last updated November 27, 2024)
An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a heap overflow, which can result in remote code execution. An attacker could provide a malformed file to the victim to trigger this vulnerability.
Attacker Value
Unknown

CVE-2017-2811

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
A code execution vulnerability exists in the Kakadu SDK 7.9's parsing of compressed JPEG 2000 images. A specially crafted JPEG 2000 file can be read by the program, and can lead to an out of bounds write causing an exploitable condition to arise.
0
Attacker Value
Unknown

CVE-2017-2812

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
A code execution vulnerability exists in the kdu_buffered_expand function of the Kakadu SDK 7.9. A specially crafted JPEG 2000 file can be read by the program and can lead to an out of bounds write causing an exploitable condition to arise.
0
Attacker Value
Unknown

CVE-2012-1410

Disclosure Date: February 29, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the History Window implementation in Kadu 0.9.0 through 0.11.0 allow remote attackers to inject arbitrary web script or HTML via a crafted (1) SMS message, (2) presence message, or (3) status description.
0
Attacker Value
Unknown

CVE-2006-0768

Disclosure Date: February 18, 2006 (last updated February 22, 2025)
Kadu 0.4.3 allows remote attackers to cause a denial of service (application crash) via a large number of image send requests.
0
Attacker Value
Unknown

CVE-2005-3960

Disclosure Date: December 01, 2005 (last updated February 22, 2025)
Kadu 0.4.2 and 0.5.0pre allows remote attackers to cause a denial of service (crash or generated traffic) via a malformed message, possibly with incomplete information.
0
Attacker Value
Unknown

CVE-2005-1852

Disclosure Date: July 26, 2005 (last updated February 22, 2025)
Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.
0