Vulnerabilities
Vulnerable Software
Jasper Project:  >> Jasper  >> 2.0.1  Security Vulnerabilities
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.
CVSS Score
7.8
EPSS Score
0.0
Published
2024-01-16
A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c
CVSS Score
5.5
EPSS Score
0.003
Published
2021-07-15
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
CVSS Score
5.5
EPSS Score
0.001
Published
2021-03-25
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
CVSS Score
5.5
EPSS Score
0.0
Published
2021-03-25
A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.
CVSS Score
5.5
EPSS Score
0.001
Published
2021-02-23
A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.
CVSS Score
7.1
EPSS Score
0.001
Published
2021-02-23
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
CVSS Score
7.8
EPSS Score
0.002
Published
2020-12-11
The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted flif file.
CVSS Score
5.5
EPSS Score
0.002
Published
2019-08-15
An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.
CVSS Score
5.5
EPSS Score
0.003
Published
2018-08-01
JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash.
CVSS Score
6.5
EPSS Score
0.003
Published
2018-03-12


Contact Us

Shodan ® - All rights reserved