Vulnerabilities > Uclouvain > Openjpeg > 1.5.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-04 | CVE-2021-3575 | Out-of-bounds Write vulnerability in multiple products A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. | 7.8 |
2021-05-13 | CVE-2020-27823 | Classic Buffer Overflow vulnerability in multiple products A flaw was found in OpenJPEG’s encoder. | 7.8 |
2021-05-13 | CVE-2020-27824 | Out-of-bounds Read vulnerability in multiple products A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. | 5.5 |
2021-01-05 | CVE-2020-27845 | Out-of-bounds Read vulnerability in multiple products There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. | 5.5 |
2021-01-05 | CVE-2020-27844 | Improper Input Validation vulnerability in multiple products A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. | 7.8 |
2021-01-05 | CVE-2020-27843 | Out-of-bounds Read vulnerability in multiple products A flaw was found in OpenJPEG in versions prior to 2.4.0. | 5.5 |
2021-01-05 | CVE-2020-27842 | Out-of-bounds Read vulnerability in multiple products There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. | 5.5 |
2021-01-05 | CVE-2020-27841 | Heap-based Buffer Overflow vulnerability in multiple products There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. | 5.5 |
2020-06-29 | CVE-2020-15389 | Use After Free vulnerability in multiple products jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. | 6.5 |
2020-01-13 | CVE-2020-6851 | Out-of-bounds Write vulnerability in multiple products OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation. | 7.5 |