Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.0% | — | Jasper Project Jasper | 15/3/2017 | 17/6/2026 | Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.12 allows remote attackers to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 4.0% | — | Jasper Project Jasper | 15/3/2017 | 17/6/2026 | The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) via vectors involving an empty sequence. | |
| Modificada | Media (5.5) | 1.6% | — | Jasper Project Jasper | 1/3/2017 | 17/6/2026 | The jpc_undo_roi function in libjasper/jpc/jpc_dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image. | |
| Modificada | Media (5.5) | 1.8% | — | Jasper Project Jasper | 1/3/2017 | 17/6/2026 | The dec_clnpass function in libjasper/jpc/jpc_t1dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via a crafted image. | |
| Modificada | Media (5.5) | 1.3% | — | Jasper Project Jasper | 1/3/2017 | 17/6/2026 | libjasper/jp2/jp2_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value. | |
| Modificada | Media (5.5) | 1.3% | — | Jasper Project Jasper | 1/3/2017 | 17/6/2026 | Integer overflow in libjasper/jpc/jpc_tsfb.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file. | |
| Modificada | Media (5.5) | 1.3% | — | Jasper Project Jasper | 1/3/2017 | 17/6/2026 | libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value. | |
| Modificada | Media (5.5) | 1.3% | — | Jasper Project Jasper | 1/3/2017 | 17/6/2026 | Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file. | |
| Modificada | Media (5.5) | 1.1% | — | Jasper Project Jasper | 1/3/2017 | 17/6/2026 | libjasper/include/jasper/jas_math.h in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value. | |
| Modificada | Alta (7.8) | 2.9% | — | Jasper Project JasperDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+4 | 15/2/2017 | 17/6/2026 | Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have unspecified impact via a crafted image. | |
| Modificada | Alta (7.8) | 3.3% | — | Jasper Project JasperOpensuseFedoraproject Fedora | 15/2/2017 | 17/6/2026 | Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image to the imginfo command. | |
| Modificada | Media (5.5) | 2.2% | — | Jasper Project JasperFedoraproject FedoraDebian Linux | 15/2/2017 | 17/6/2026 | The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP image to the imginfo command. | |
| Modificada | Media (5.5) | 2.2% | — | Jasper Project JasperDebian LinuxFedoraproject Fedora | 15/2/2017 | 17/6/2026 | The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo command. | |
| Modificada | Media (5.5) | 2.5% | — | Jasper Project JasperFedoraproject Fedora | 15/2/2017 | 17/6/2026 | The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted BMP image in an imginfo command. | |
| Modificada | Media (5.5) | 1.5% | — | Jasper Project Jasper | 13/1/2017 | 17/6/2026 | The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (assertion failure) via a crafted file. | |
| Modificada | Media (5.5) | 1.6% | — | Jasper Project Jasper | 13/1/2017 | 17/6/2026 | The jpc_dec_tilefini function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. | |
| Modificada | Media (5.7) | 3.0% | — | Canonical Ubuntu LinuxJasper Project Jasper | 13/4/2016 | 17/6/2026 | Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file. | |
| Modificada | Alta (7.6) | 3.3% | — | Canonical Ubuntu LinuxJasper Project Jasper | 13/4/2016 | 17/6/2026 | Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file, a different vulnerability than CVE-2014-8137. | |
| Modificada | Media (6.5) | 3.0% | — | Jasper Project Jasper | 8/2/2016 | 17/6/2026 | The jas_matrix_clip function in jas_seq.c in JasPer 1.900.1 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted JPEG 2000 image. | |
| Modificada | Media (6.5) | 2.3% | — | Jasper Project Jasper | 20/1/2016 | 17/6/2026 | The jpc_pi_nextcprl function in JasPer 1.900.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image. | |
| Modificada | Media (6.8) | 14% | — | Jasper Project JasperDebian LinuxRedhat Enterprise LinuxOpensuse | 26/1/2015 | 17/6/2026 | Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image. | |
| Modificada | Alta (7.5) | 17% | — | OpensuseDebian LinuxRedhat Enterprise LinuxJasper Project Jasper | 26/1/2015 | 17/6/2026 | Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 19% | — | Redhat Enterprise LinuxJasper Project Jasper | 24/12/2014 | 17/6/2026 | Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file. | |
| Modificada | Media (6.8) | 15% | — | Jasper Project JasperRedhat Enterprise Linux | 24/12/2014 | 17/6/2026 | Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file. | |
| Modificada | Alta (7.5) | 18% | — | Jasper Project Jasper | 8/12/2014 | 17/6/2026 | Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow. |