Vulnerabilities > Jasper Project > Jasper > 1.900.2

DATE CVE VULNERABILITY TITLE RISK
2018-03-12 CVE-2016-9600 NULL Pointer Dereference vulnerability in multiple products
JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files.
network
low complexity
jasper-project canonical redhat CWE-476
6.5
2018-03-09 CVE-2016-9591 Use After Free vulnerability in multiple products
JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.
local
low complexity
jasper-project redhat debian CWE-416
5.5
2017-03-23 CVE-2016-9557 Integer Overflow or Wraparound vulnerability in Jasper Project Jasper
Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file.
local
low complexity
jasper-project CWE-190
5.5
2017-03-23 CVE-2016-9398 Reachable Assertion vulnerability in multiple products
The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
7.5
2017-03-23 CVE-2016-9396 Unspecified vulnerability in Jasper Project Jasper
The JPC_NOMINALGAIN function in jpc/jpc_t1cod.c in JasPer through 2.0.12 allows remote attackers to cause a denial of service (JPC_COX_RFT assertion failure) via unspecified vectors.
network
low complexity
jasper-project
7.5
2017-03-23 CVE-2016-9395 Improper Input Validation vulnerability in Jasper Project Jasper
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
local
low complexity
jasper-project CWE-20
5.5
2017-03-23 CVE-2016-9394 Improper Input Validation vulnerability in Jasper Project Jasper
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
local
low complexity
jasper-project CWE-20
5.5
2017-03-23 CVE-2016-9392 Unspecified vulnerability in Jasper Project Jasper
The calcstepsizes function in jpc_dec.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
local
low complexity
jasper-project
5.5
2017-03-23 CVE-2016-9391 Unspecified vulnerability in Jasper Project Jasper
The jpc_bitstream_getbits function in jpc_bs.c in JasPer before 2.0.10 allows remote attackers to cause a denial of service (assertion failure) via a very large integer.
network
low complexity
jasper-project
7.5
2017-03-23 CVE-2016-9390 Improper Input Validation vulnerability in Jasper Project Jasper
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
local
low complexity
jasper-project CWE-20
5.5