Vulnerabilities > Uclouvain

DATE CVE VULNERABILITY TITLE RISK
2021-01-05 CVE-2020-27845 Heap-Based Buffer Overflow vulnerability in Uclouvain Openjpeg
There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0.
network
uclouvain CWE-122
4.3
2021-01-05 CVE-2020-27844 Improper Input Validation vulnerability in Uclouvain Openjpeg
A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0.
network
uclouvain CWE-20
8.3
2021-01-05 CVE-2020-27843 Out-Of-Bounds Read vulnerability in Uclouvain Openjpeg
A flaw was found in OpenJPEG in versions prior to 2.4.0.
network
uclouvain CWE-125
7.1
2021-01-05 CVE-2020-27842 Out-Of-Bounds Read vulnerability in Uclouvain Openjpeg
There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0.
network
uclouvain CWE-125
4.3
2021-01-05 CVE-2020-27841 Heap-Based Buffer Overflow vulnerability in Uclouvain Openjpeg
There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c.
network
uclouvain CWE-122
4.3
2020-06-29 CVE-2020-15389 USE After Free vulnerability in multiple products
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor.
5.8
2019-09-05 CVE-2018-21010 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Uclouvain Openjpeg
OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.
network
uclouvain CWE-119
6.8
2019-06-26 CVE-2018-20847 Integer Overflow OR Wraparound vulnerability in Uclouvain Openjpeg
An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.
network
uclouvain CWE-190
6.8
2019-06-26 CVE-2018-20846 Improper Input Validation vulnerability in Uclouvain Openjpeg
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
network
uclouvain CWE-20
4.3
2019-06-26 CVE-2018-20845 Divide BY Zero vulnerability in Uclouvain Openjpeg
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
network
uclouvain CWE-369
4.3