Jasper Project

Jasper

102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.64%
  • Veröffentlicht 29.08.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack.

Exploit
  • EPSS 1.01%
  • Veröffentlicht 29.08.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service attack.

Exploit
  • EPSS 2.66%
  • Veröffentlicht 29.08.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack.

  • EPSS 0.38%
  • Veröffentlicht 02.08.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

  • EPSS 0.23%
  • Veröffentlicht 25.07.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

  • EPSS 1.61%
  • Veröffentlicht 17.07.2017 13:18:17
  • Zuletzt bearbeitet 20.04.2025 01:37:25

JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.

  • EPSS 0.4%
  • Veröffentlicht 21.06.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c.

  • EPSS 0.41%
  • Veröffentlicht 28.03.2017 14:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of ...

  • EPSS 4.11%
  • Veröffentlicht 23.03.2017 18:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.

  • EPSS 2.14%
  • Veröffentlicht 23.03.2017 18:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.