Vulnerability Details CVE-2016-9262
Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.3%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 4.3
Products affected by CVE-2016-9262
-
cpe:2.3:a:jasper_project:jasper:-
-
cpe:2.3:a:jasper_project:jasper:1.900.1
-
cpe:2.3:a:jasper_project:jasper:1.900.10
-
cpe:2.3:a:jasper_project:jasper:1.900.11
-
cpe:2.3:a:jasper_project:jasper:1.900.12
-
cpe:2.3:a:jasper_project:jasper:1.900.13
-
cpe:2.3:a:jasper_project:jasper:1.900.14
-
cpe:2.3:a:jasper_project:jasper:1.900.15
-
cpe:2.3:a:jasper_project:jasper:1.900.16
-
cpe:2.3:a:jasper_project:jasper:1.900.17
-
cpe:2.3:a:jasper_project:jasper:1.900.18
-
cpe:2.3:a:jasper_project:jasper:1.900.19
-
cpe:2.3:a:jasper_project:jasper:1.900.2
-
cpe:2.3:a:jasper_project:jasper:1.900.20
-
cpe:2.3:a:jasper_project:jasper:1.900.21
-
cpe:2.3:a:jasper_project:jasper:1.900.3
-
cpe:2.3:a:jasper_project:jasper:1.900.4
-
cpe:2.3:a:jasper_project:jasper:1.900.5
-
cpe:2.3:a:jasper_project:jasper:1.900.6
-
cpe:2.3:a:jasper_project:jasper:1.900.7
-
cpe:2.3:a:jasper_project:jasper:1.900.8
-
cpe:2.3:a:jasper_project:jasper:1.900.9