CVE-2017-13746
- EPSS 1.64%
- Veröffentlicht 29.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack.
CVE-2017-13747
- EPSS 1.01%
- Veröffentlicht 29.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
CVE-2017-13748
- EPSS 2.66%
- Veröffentlicht 29.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack.
CVE-2015-5203
- EPSS 0.38%
- Veröffentlicht 02.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
CVE-2015-5221
- EPSS 0.23%
- Veröffentlicht 25.07.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
CVE-2017-1000050
- EPSS 1.61%
- Veröffentlicht 17.07.2017 13:18:17
- Zuletzt bearbeitet 20.04.2025 01:37:25
JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
CVE-2017-9782
- EPSS 0.4%
- Veröffentlicht 21.06.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c.
CVE-2016-8884
- EPSS 0.41%
- Veröffentlicht 28.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of ...
CVE-2016-9398
- EPSS 4.11%
- Veröffentlicht 23.03.2017 18:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
CVE-2016-9399
- EPSS 2.14%
- Veröffentlicht 23.03.2017 18:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.