Vulnerabilities > Kakadusoftware > Kakadu SDK

DATE CVE VULNERABILITY TITLE RISK
2023-12-20 CVE-2023-6562 Unrestricted Upload of File with Dangerous Type vulnerability in Kakadusoftware Kakadu SDK
JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a specially-crafted the image that is displayed back to the attacker.
network
low complexity
kakadusoftware CWE-434
7.5
2018-04-24 CVE-2017-2812 Out-of-bounds Write vulnerability in Kakadusoftware Kakadu SDK 7.9
A code execution vulnerability exists in the kdu_buffered_expand function of the Kakadu SDK 7.9.
6.8
2018-04-24 CVE-2017-2811 Out-of-bounds Write vulnerability in Kakadusoftware Kakadu SDK 7.9
A code execution vulnerability exists in the Kakadu SDK 7.9's parsing of compressed JPEG 2000 images.
6.8