Vulnerabilities > Dropbox > Lepton > 1.2.1

DATE CVE VULNERABILITY TITLE RISK
2022-02-28 CVE-2022-26181 Out-of-bounds Write vulnerability in Dropbox Lepton 1.2.1
Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.
network
dropbox CWE-787
6.8
2019-04-23 CVE-2018-20820 Integer Overflow or Wraparound vulnerability in Dropbox Lepton 1.2.1
read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.
network
dropbox CWE-190
4.3
2019-04-23 CVE-2018-20819 Out-of-bounds Write vulnerability in Dropbox Lepton 1.2.1
io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file.
network
dropbox CWE-787
6.8
2018-06-11 CVE-2018-12108 Improper Input Validation vulnerability in Dropbox Lepton 1.2.1
An issue was discovered in Dropbox Lepton 1.2.1.
network
dropbox CWE-20
4.3
2017-05-10 CVE-2017-8891 DEPRECATED: Use of Uninitialized Resource vulnerability in Dropbox Lepton 1.2.1
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.
network
dropbox CWE-1187
4.3
2017-04-05 CVE-2017-7448 Divide By Zero vulnerability in Dropbox Lepton 1.2.1
The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image.
network
dropbox CWE-369
4.3