Vulnerabilities
Vulnerable Software
Kakadusoftware:  Security Vulnerabilities
JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a specially-crafted the image that is displayed back to the attacker.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-12-20
An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a heap overflow, which can result in remote code execution. An attacker could provide a malformed file to the victim to trigger this vulnerability.
CVSS Score
8.1
EPSS Score
0.052
Published
2019-12-12
A code execution vulnerability exists in the Kakadu SDK 7.9's parsing of compressed JPEG 2000 images. A specially crafted JPEG 2000 file can be read by the program, and can lead to an out of bounds write causing an exploitable condition to arise.
CVSS Score
8.8
EPSS Score
0.003
Published
2018-04-24
A code execution vulnerability exists in the kdu_buffered_expand function of the Kakadu SDK 7.9. A specially crafted JPEG 2000 file can be read by the program and can lead to an out of bounds write causing an exploitable condition to arise.
CVSS Score
8.8
EPSS Score
0.004
Published
2018-04-24


Contact Us

Shodan ® - All rights reserved