Vulnerabilities > Libjpeg Turbo > High

DATE CVE VULNERABILITY TITLE RISK
2023-08-22 CVE-2021-29390 Out-of-bounds Write vulnerability in multiple products
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
network
low complexity
libjpeg-turbo fedoraproject CWE-787
7.1
2021-06-01 CVE-2020-17541 Out-of-bounds Write vulnerability in Libjpeg-Turbo
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component.
network
low complexity
libjpeg-turbo CWE-787
8.8
2020-06-03 CVE-2020-13790 Out-of-bounds Read vulnerability in multiple products
libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.
network
low complexity
libjpeg-turbo mozilla CWE-125
8.1
2018-12-21 CVE-2018-20330 Integer Overflow or Wraparound vulnerability in Libjpeg-Turbo 2.0.1
The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.
network
low complexity
libjpeg-turbo CWE-190
8.8
2017-02-13 CVE-2016-3616 NULL Pointer Dereference vulnerability in multiple products
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
network
low complexity
libjpeg-turbo redhat debian canonical CWE-476
8.8