CVE-2025-8837
- EPSS 0.05%
- Published 11.08.2025 08:15:26
- Last modified 16.09.2025 18:55:31
A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The manipulation leads to use after free. An attack has to be approached loca...
CVE-2025-8836
- EPSS 0.03%
- Published 11.08.2025 07:32:08
- Last modified 16.09.2025 18:59:52
A vulnerability was determined in JasPer up to 4.2.5. Affected by this issue is the function jpc_floorlog2 of the file src/libjasper/jpc/jpc_enc.c of the component JPEG2000 Encoder. The manipulation leads to reachable assertion. The attack needs to b...
CVE-2025-8835
- EPSS 0.03%
- Published 11.08.2025 07:15:32
- Last modified 16.09.2025 17:52:32
A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. The manipulation leads to null pointe...
CVE-2024-31744
- EPSS 0.03%
- Published 19.04.2024 13:15:13
- Last modified 21.11.2024 09:13:50
In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.
CVE-2023-51257
- EPSS 0.03%
- Published 16.01.2024 02:15:28
- Last modified 16.06.2025 19:15:26
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.
CVE-2022-2963
- EPSS 0.1%
- Published 14.10.2022 18:15:15
- Last modified 15.05.2025 15:15:53
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
CVE-2022-40755
- EPSS 0.15%
- Published 16.09.2022 22:15:12
- Last modified 21.11.2024 07:21:59
JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.
CVE-2021-27845
- EPSS 0.25%
- Published 15.07.2021 16:15:09
- Last modified 21.11.2024 05:58:37
A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c
CVE-2021-3467
- EPSS 0.07%
- Published 25.03.2021 19:15:15
- Last modified 21.11.2024 06:21:36
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to cra...
CVE-2021-3443
- EPSS 0.04%
- Published 25.03.2021 19:15:14
- Last modified 21.11.2024 06:21:32
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when open...