Vulnerabilities
Vulnerable Software
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
CVSS Score
8.8
EPSS Score
0.006
Published
2021-06-01
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-03-07


Contact Us

Shodan ® - All rights reserved