Show filters
77 Total Results
Displaying 1-10 of 77
Sort by:
Attacker Value
Unknown

CVE-2022-1122

Disclosure Date: March 29, 2022 (last updated November 08, 2023)
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
Attacker Value
Unknown

CVE-2021-3575

Disclosure Date: March 04, 2022 (last updated October 07, 2023)
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
Attacker Value
Unknown

CVE-2020-27823

Disclosure Date: May 13, 2021 (last updated November 08, 2023)
A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Attacker Value
Unknown

CVE-2020-27824

Disclosure Date: May 13, 2021 (last updated November 08, 2023)
A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-29338

Disclosure Date: April 14, 2021 (last updated November 08, 2023)
Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.
Attacker Value
Unknown

CVE-2020-27814

Disclosure Date: January 26, 2021 (last updated November 28, 2024)
A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.
Attacker Value
Unknown

CVE-2020-27841

Disclosure Date: January 05, 2021 (last updated November 08, 2023)
There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to application availability.
Attacker Value
Unknown

CVE-2020-27845

Disclosure Date: January 05, 2021 (last updated November 08, 2023)
There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw is to application availability.
Attacker Value
Unknown

CVE-2020-27842

Disclosure Date: January 05, 2021 (last updated November 08, 2023)
There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.
Attacker Value
Unknown

CVE-2020-27843

Disclosure Date: January 05, 2021 (last updated November 08, 2023)
A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system availability.