Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.2% | — | Libjpeg-turboFedoraproject Fedora | 10/3/2021 | 17/6/2026 | Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image. | |
| Modificada | Alta (7.1) | 1.1% | — | IJG Libjpeg | 15/6/2020 | 17/6/2026 | In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers. | |
| Modificada | Alta (7.1) | 1.5% | — | IJG LibjpegDebian Linux | 15/6/2020 | 17/6/2026 | In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption. | |
| Modificada | Alta (8.1) | 3.2% | — | Libjpeg-turboMozilla Mozjpeg | 3/6/2020 | 17/6/2026 | libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file. | |
| Modificada | Media (5.5) | 0.95% | — | Libjpeg-turbo | 18/7/2019 | 17/6/2026 | In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and height values in the image header. NOTE: the vendor's expectation, for use cases in which this memory usage would be a denial of service, is that the application should… | |
| Modificada | Media (6.5) | 3.1% | — | Libjpeg-turboMozilla MozjpegFedoraproject FedoraDebian Linux+1 | 7/3/2019 | 17/6/2026 | get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries. | |
| Modificada | Alta (8.8) | 2.0% | — | Libjpeg-turbo | 21/12/2018 | 17/6/2026 | The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench. | |
| Modificada | Media (6.5) | 1.7% | — | Libjpeg-turbo | 29/11/2018 | 17/6/2026 | libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg. | |
| Modificada | Media (6.5) | 3.4% | — | Libjpeg-turboCanonical Ubuntu LinuxDebian Linux | 18/6/2018 | 17/6/2026 | libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image. | |
| Modificada | Alta (7.5) | 3.2% | — | IJG Libjpeg | 6/6/2018 | 17/6/2026 | libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF. | |
| Modificada | Media (6.5) | 2.4% | — | IJG LibjpegDebian LinuxCanonical Ubuntu Linux | 16/5/2018 | 17/6/2026 | An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file. | |
| Modificada | Media (6.5) | 2.6% | — | IJG LibjpegDebian LinuxCanonical Ubuntu Linux | 16/5/2018 | 17/6/2026 | An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file. | |
| Modificada | Media (6.5) | 4.8% | — | IJG LibjpegDebian LinuxCanonical Ubuntu LinuxNetapp Oncommand Unified Manager+9 | 16/5/2018 | 17/6/2026 | An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file. | |
| Modificada | Media (6.5) | 2.4% | — | Libjpeg-turbo | 11/10/2017 | 17/6/2026 | libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file. | |
| Modificada | Media (6.5) | 3.2% | — | Libjpeg-turboFedoraproject FedoraCanonical Ubuntu Linux | 10/10/2017 | 17/6/2026 | libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker. | |
| Modificada | Alta (8.8) | 8.2% | — | D.r.commander Libjpeg-turbo | 27/7/2017 | 17/6/2026 | The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file. NOTE: Maintainer asserts the issue is due to a bug in downstream code caused by misuse… | |
| Modificada | Alta (8.8) | 4.4% | — | Libjpeg-turboRedhat Enterprise LinuxDebian LinuxCanonical Ubuntu Linux | 13/2/2017 | 17/6/2026 | The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file. | |
| Modificada | Media (5) | 9.7% | — | Google ChromeOracle SolarisArtifex GPL GhostscriptLibjpeg-turbo+7 | 19/11/2013 | 17/6/2026 | The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows… | |
| Modificada | Alta (8.8) | 4.8% | — | D.r.commander Libjpeg-turbo | 13/8/2012 | 16/6/2026 | Heap-based buffer overflow in the get_sos function in jdmarker.c in libjpeg-turbo 1.2.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large component count in the header of a JPEG image. |