Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2017
The jpc_irct and jpc_iict functions in jpc_mct.c in JasPer before 1.900.14 allow remote attackers to cause a denial of service (assertion failure).
CVSS Score
7.5
EPSS Score
0.016
Published
2017-03-23
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
CVSS Score
5.5
EPSS Score
0.005
Published
2017-03-23
The jpc_bitstream_getbits function in jpc_bs.c in JasPer before 2.0.10 allows remote attackers to cause a denial of service (assertion failure) via a very large integer.
CVSS Score
7.5
EPSS Score
0.012
Published
2017-03-23
The calcstepsizes function in jpc_dec.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
CVSS Score
5.5
EPSS Score
0.005
Published
2017-03-23
The jpc_pi_nextrpcl function in jpc_t2cod.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
CVSS Score
5.5
EPSS Score
0.005
Published
2017-03-23
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
CVSS Score
5.5
EPSS Score
0.005
Published
2017-03-23
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
CVSS Score
5.5
EPSS Score
0.004
Published
2017-03-23
The JPC_NOMINALGAIN function in jpc/jpc_t1cod.c in JasPer through 2.0.12 allows remote attackers to cause a denial of service (JPC_COX_RFT assertion failure) via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.046
Published
2017-03-23
The jpc_dequantize function in jpc_dec.c in JasPer 1.900.13 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.018
Published
2017-03-23
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.
CVSS Score
9.8
EPSS Score
0.579
Published
2017-03-23


Contact Us

Shodan ® - All rights reserved