Jasper Project
Jasper Project Jasper: vulnerabilidades y CVE
Jasper Project Jasper tiene 101 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE101
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-8837 | Baja (1.9) | 0.23% | — | 11 ago 2025 | A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The manipulation leads to use after free. An… |
| CVE-2025-8836 | Baja (1.9) | 0.21% | — | 11 ago 2025 | A vulnerability was determined in JasPer up to 4.2.5. Affected by this issue is the function jpc_floorlog2 of the file src/libjasper/jpc/jpc_enc.c of the component JPEG2000 Encoder. The manipulation leads to reachable… |
| CVE-2025-8835 | Baja (1.9) | 0.21% | — | 11 ago 2025 | A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. The… |
| CVE-2023-51257 | Alta (7.8) | 0.26% | — | 16 ene 2024 | An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code. |
| CVE-2022-2963 | Alta (7.5) | 1.4% | — | 14 oct 2022 | A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault. |
| CVE-2022-40755 | Media (5.5) | 0.38% | — | 16 sept 2022 | JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c. |
| CVE-2021-27845 | Media (5.5) | 0.65% | — | 15 jul 2021 | A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c |
| CVE-2021-3467 | Media (5.5) | 0.63% | — | 25 mar 2021 | A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application… |
| CVE-2021-3443 | Media (5.5) | 0.76% | — | 25 mar 2021 | A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the… |
| CVE-2021-26927 | Media (5.5) | 1.1% | — | 23 feb 2021 | A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service. |
| CVE-2021-26926 | Alta (7.1) | 1.2% | — | 23 feb 2021 | A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash. |
| CVE-2021-3272 | Media (5.5) | 1.1% | — | 27 ene 2021 | jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components. |
| CVE-2020-27828 | Alta (7.8) | 1.4% | — | 11 dic 2020 | There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality,… |
| CVE-2015-8751 | Alta (8.8) | 2.5% | — | 17 feb 2020 | Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation. |
| CVE-2017-14232 | Media (5.5) | 1.2% | — | 15 ago 2019 | The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted flif file. |
| CVE-2018-20622 | Media (6.5) | 2.9% | — | 31 dic 2018 | JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. |
| CVE-2018-20584 | Media (6.5) | 2.9% | — | 30 dic 2018 | JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format. |
| CVE-2018-20570 | Media (6.5) | 2.2% | — | 28 dic 2018 | jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read. |
| CVE-2018-19543 | Alta (7.8) | 1.6% | — | 26 nov 2018 | An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c. |
| CVE-2018-19542 | Media (6.5) | 1.9% | — | 26 nov 2018 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service. |
| CVE-2018-19541 | Alta (8.8) | 2.8% | — | 26 nov 2018 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25,… |
| CVE-2018-19540 | Alta (8.8) | 2.3% | — | 26 nov 2018 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25,… |
| CVE-2018-19539 | Media (6.5) | 1.9% | — | 26 nov 2018 | An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service. |
| CVE-2018-19139 | Media (5.5) | 1.7% | — | 9 nov 2018 | An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c. |
| CVE-2018-18873 | Media (5.5) | 1.4% | — | 31 oct 2018 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c. |
| CVE-2016-9583 | Alta (7.8) | 1.9% | — | 1 ago 2018 | An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input. |
| CVE-2016-8654 | Alta (7.8) | 1.9% | — | 1 ago 2018 | A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected. |
| CVE-2018-9154 | Alta (7.5) | 3.5% | — | 4 may 2018 | There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a… |
| CVE-2018-9252 | Media (6.5) | 2.0% | — | 4 abr 2018 | JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c. |
| CVE-2018-9055 | Media (5.5) | 1.7% | — | 27 mar 2018 | JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_firstone in libjasper/jpc/jpc_math.c. |