Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.1% | — | Jasper Project JasperFedoraproject Fedora | 27/1/2021 | 17/6/2026 | jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components. | |
| Modificada | Alta (7.8) | 1.4% | — | Jasper Project JasperFedoraproject Fedora | 11/12/2020 | 17/6/2026 | There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability. | |
| Modificada | Alta (8.8) | 5.4% | — | Tibco Jasperreports LibraryTibco Jasperreports ServerOracle Retail Order Broker | 20/5/2020 | 17/6/2026 | The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an… | |
| Modificada | Crítica (9.8) | 3.5% | — | Tibco Jasperreports ServerOracle Retail Order Broker | 20/5/2020 | 17/6/2026 | The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server… | |
| Modificada | Alta (8.8) | 2.5% | — | Jasper Project Jasper | 17/2/2020 | 17/6/2026 | Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation. | |
| Modificada | Media (5.5) | 1.2% | — | FlifJasper Project Jasper | 15/8/2019 | 17/6/2026 | The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted flif file. | |
| Modificada | Alta (7.7) | 1.0% | — | Tibco Jasperreports Server | 7/3/2019 | 17/6/2026 | The SOAP API component vulnerability of TIBCO Software Inc.'s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authenticated user to copy text files from the host operating system. Affected releases are TIBCO Software Inc.'s TIBCO… | |
| Modificada | Media (5.4) | 1.2% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS contains a persistent cross site scripting… | |
| Modificada | Crítica (9.8) | 3.1% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows… | |
| Analizada | Media (6.5) | 79% | ⚠ Explotación activa | Tibco Jasperreports LibraryTibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO… | |
| Modificada | Alta (7.5) | 1.7% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a race-condition vulnerability… | |
| Modificada | Media (6.5) | 2.9% | — | Jasper Project JasperDebian Linux | 31/12/2018 | 17/6/2026 | JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. | |
| Modificada | Media (6.5) | 2.9% | — | Jasper Project JasperDebian LinuxOracle Outside IN Technology | 30/12/2018 | 17/6/2026 | JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format. | |
| Modificada | Media (6.5) | 2.2% | — | Jasper Project JasperDebian Linux | 28/12/2018 | 17/6/2026 | jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read. | |
| Modificada | Alta (7.8) | 1.6% | — | Jasper Project JasperCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+1 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c. | |
| Modificada | Media (6.5) | 1.9% | — | Jasper Project JasperCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service. | |
| Modificada | Alta (8.8) | 2.8% | — | Jasper Project JasperCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5,… | |
| Modificada | Alta (8.8) | 2.3% | — | Jasper Project JasperSuse Linux Enterprise DesktopSuse Linux Enterprise ServerDebian Linux | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5,… | |
| Modificada | Media (6.5) | 1.9% | — | Jasper Project JasperSuse Linux Enterprise DesktopSuse Linux Enterprise ServerDebian Linux+1 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service. | |
| Modificada | Media (5.5) | 1.7% | — | Jasper Project JasperRedhat FedoraDebian Linux | 9/11/2018 | 17/6/2026 | An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c. | |
| Modificada | Media (5.5) | 1.4% | — | Jasper Project JasperCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+1 | 31/10/2018 | 17/6/2026 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c. | |
| Modificada | Alta (7.8) | 1.9% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+4 | 1/8/2018 | 17/6/2026 | An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input. | |
| Modificada | Alta (7.8) | 1.9% | — | Jasper Project JasperDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 1/8/2018 | 17/6/2026 | A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected. | |
| Modificada | Alta (7.5) | 3.5% | — | Jasper Project Jasper | 4/5/2018 | 17/6/2026 | There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a different vulnerability than CVE-2017-13745. | |
| Modificada | Media (5.4) | 0.59% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 17/4/2018 | 17/6/2026 | The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow,… |