Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2022-4104
Disclosure Date: November 28, 2022 (last updated February 24, 2025)
A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compression tool, resulting in a denial-of-service.
0
Attacker Value
Unknown
CVE-2022-26181
Disclosure Date: February 28, 2022 (last updated February 23, 2025)
Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.
0
Attacker Value
Unknown
CVE-2018-20819
Disclosure Date: April 23, 2019 (last updated November 27, 2024)
io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be (incorrectly) larger than the maximum file size.
0
Attacker Value
Unknown
CVE-2018-20820
Disclosure Date: April 23, 2019 (last updated November 27, 2024)
read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.
0
Attacker Value
Unknown
CVE-2018-12108
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file.
0
Attacker Value
Unknown
CVE-2017-8891
Disclosure Date: May 10, 2017 (last updated November 26, 2024)
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.
0
Attacker Value
Unknown
CVE-2017-7448
Disclosure Date: April 05, 2017 (last updated November 26, 2024)
The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image.
0