Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

137 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.1%—Jasper Project JasperFedoraproject Fedora27/1/202117/6/2026
jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.
ModificadaAlta (7.8)1.4%—Jasper Project JasperFedoraproject Fedora11/12/202017/6/2026
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
ModificadaAlta (8.8)5.4%—Tibco Jasperreports LibraryTibco Jasperreports ServerOracle Retail Order Broker20/5/202017/6/2026
The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an…
ModificadaCrítica (9.8)3.5%—Tibco Jasperreports ServerOracle Retail Order Broker20/5/202017/6/2026
The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server…
ModificadaAlta (8.8)2.5%—Jasper Project Jasper17/2/202017/6/2026
Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.
ModificadaMedia (5.5)1.2%—FlifJasper Project Jasper15/8/201917/6/2026
The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted flif file.
ModificadaAlta (7.7)1.0%—Tibco Jasperreports Server7/3/201917/6/2026
The SOAP API component vulnerability of TIBCO Software Inc.'s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authenticated user to copy text files from the host operating system. Affected releases are TIBCO Software Inc.'s TIBCO…
ModificadaMedia (5.4)1.2%—Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics7/3/201917/6/2026
The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS contains a persistent cross site scripting…
ModificadaCrítica (9.8)3.1%—Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics7/3/201917/6/2026
The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows…
AnalizadaMedia (6.5)79%⚠ Explotación activaTibco Jasperreports LibraryTibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics7/3/201917/6/2026
The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO…
ModificadaAlta (7.5)1.7%—Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics7/3/201917/6/2026
The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a race-condition vulnerability…
ModificadaMedia (6.5)2.9%—Jasper Project JasperDebian Linux31/12/201817/6/2026
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
ModificadaMedia (6.5)2.9%—Jasper Project JasperDebian LinuxOracle Outside IN Technology30/12/201817/6/2026
JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format.
ModificadaMedia (6.5)2.2%—Jasper Project JasperDebian Linux28/12/201817/6/2026
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
ModificadaAlta (7.8)1.6%—Jasper Project JasperCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+126/11/201817/6/2026
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
ModificadaMedia (6.5)1.9%—Jasper Project JasperCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+226/11/201817/6/2026
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.
ModificadaAlta (8.8)2.8%—Jasper Project JasperCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+126/11/201817/6/2026
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5,…
ModificadaAlta (8.8)2.3%—Jasper Project JasperSuse Linux Enterprise DesktopSuse Linux Enterprise ServerDebian Linux26/11/201817/6/2026
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5,…
ModificadaMedia (6.5)1.9%—Jasper Project JasperSuse Linux Enterprise DesktopSuse Linux Enterprise ServerDebian Linux+126/11/201817/6/2026
An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.
ModificadaMedia (5.5)1.7%—Jasper Project JasperRedhat FedoraDebian Linux9/11/201817/6/2026
An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.
ModificadaMedia (5.5)1.4%—Jasper Project JasperCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+131/10/201817/6/2026
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
ModificadaAlta (7.8)1.9%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+41/8/201817/6/2026
An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.
ModificadaAlta (7.8)1.9%—Jasper Project JasperDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+31/8/201817/6/2026
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
ModificadaAlta (7.5)3.5%—Jasper Project Jasper4/5/201817/6/2026
There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a different vulnerability than CVE-2017-13745.
ModificadaMedia (5.4)0.59%—Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics17/4/201817/6/2026
The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow,…