Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.36%—Libjpeg-turboAI26/8/20269/9/2026
libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a division-by-zero in alloc_sarray(), causing a…
AplazadaMedia (6.9)0.36%—Libjpeg-turboAINeka-nat CupochAI27/1/202617/6/2026
Out-of-bounds Write vulnerability in neka-nat cupoch (third_party/libjpeg-turbo/libjpeg-turbo modules). This vulnerability is associated with program files tjbench.C. This issue affects cupoch.
ModificadaAlta (7.1)0.82%—Libjpeg-turboFedoraproject Fedora22/8/202317/6/2026
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
ModificadaMedia (6.5)1.2%—Libjpeg-turbo25/5/202317/6/2026
A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the sample data type exceeds the valid sample range, hence, an attacker could craft a 12-bit…
ModificadaMedia (5.5)0.28%—Libjpeg-turbo31/8/202217/6/2026
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
ModificadaMedia (5.5)1.1%—Libjpeg-turbo18/6/202217/6/2026
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.
ModificadaAlta (8.8)2.7%—Libjpeg-turbo1/6/202117/6/2026
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
ModificadaMedia (6.5)1.2%—Libjpeg-turboFedoraproject Fedora10/3/202117/6/2026
Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.
ModificadaAlta (8.1)3.2%—Libjpeg-turboMozilla Mozjpeg3/6/202017/6/2026
libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.
ModificadaMedia (5.5)0.95%—Libjpeg-turbo18/7/201917/6/2026
In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and height values in the image header. NOTE: the vendor's expectation, for use cases in which this memory usage would be a denial of service, is that the application should…
ModificadaMedia (6.5)3.1%—Libjpeg-turboMozilla MozjpegFedoraproject FedoraDebian Linux+17/3/201917/6/2026
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
ModificadaAlta (8.8)2.0%—Libjpeg-turbo21/12/201817/6/2026
The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.
ModificadaMedia (6.5)1.7%—Libjpeg-turbo29/11/201817/6/2026
libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.
ModificadaMedia (6.5)3.4%—Libjpeg-turboCanonical Ubuntu LinuxDebian Linux18/6/201817/6/2026
libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.
ModificadaMedia (6.5)2.4%—Libjpeg-turbo11/10/201717/6/2026
libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.
ModificadaMedia (6.5)3.2%—Libjpeg-turboFedoraproject FedoraCanonical Ubuntu Linux10/10/201717/6/2026
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
ModificadaAlta (8.8)8.2%—D.r.commander Libjpeg-turbo27/7/201717/6/2026
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file. NOTE: Maintainer asserts the issue is due to a bug in downstream code caused by misuse…
ModificadaAlta (8.8)4.4%—Libjpeg-turboRedhat Enterprise LinuxDebian LinuxCanonical Ubuntu Linux13/2/201717/6/2026
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
ModificadaMedia (5)9.7%—Google ChromeOracle SolarisArtifex GPL GhostscriptLibjpeg-turbo+719/11/201317/6/2026
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows…
ModificadaAlta (8.8)4.8%—D.r.commander Libjpeg-turbo13/8/201216/6/2026
Heap-based buffer overflow in the get_sos function in jdmarker.c in libjpeg-turbo 1.2.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large component count in the header of a JPEG image.