Vulnerabilities
Vulnerable Software
JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.
CVSS Score
5.5
EPSS Score
0.003
Published
2018-03-09
The jpc_bitstream_getbits function in jpc_bs.c in JasPer before 2.0.10 allows remote attackers to cause a denial of service (assertion failure) via a very large integer.
CVSS Score
7.5
EPSS Score
0.017
Published
2017-03-23
The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.
CVSS Score
5.5
EPSS Score
0.002
Published
2017-03-15
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.
CVSS Score
5.5
EPSS Score
0.001
Published
2017-03-15
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote attackers to have unspecified impact via a crafted image.
CVSS Score
7.8
EPSS Score
0.002
Published
2017-03-15


Contact Us

Shodan ® - All rights reserved