Vulnerabilities > Uclouvain > Openjpeg > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-06-26 CVE-2018-20846 Improper Input Validation vulnerability in Uclouvain Openjpeg
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
network
low complexity
uclouvain CWE-20
6.5
2019-06-26 CVE-2018-20845 Divide By Zero vulnerability in Uclouvain Openjpeg
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
network
low complexity
uclouvain CWE-369
6.5
2019-01-28 CVE-2019-6988 Allocation of Resources Without Limits or Throttling vulnerability in Uclouvain Openjpeg 2.3.0
An issue was discovered in OpenJPEG 2.3.0.
network
low complexity
uclouvain CWE-770
6.5
2018-10-09 CVE-2018-18088 NULL Pointer Dereference vulnerability in multiple products
OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c
network
low complexity
uclouvain debian CWE-476
6.5
2018-08-01 CVE-2016-9572 A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images.
network
low complexity
uclouvain debian
6.5
2018-02-04 CVE-2018-6616 Resource Exhaustion vulnerability in multiple products
In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c.
local
low complexity
uclouvain debian canonical oracle CWE-400
5.5
2018-01-19 CVE-2018-5785 Integer Overflow or Wraparound vulnerability in multiple products
In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c).
network
low complexity
uclouvain debian canonical CWE-190
6.5
2018-01-16 CVE-2018-5727 Integer Overflow or Wraparound vulnerability in Uclouvain Openjpeg 2.3.0
In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c).
network
low complexity
uclouvain CWE-190
6.5
2017-10-18 CVE-2015-1239 Double Free vulnerability in multiple products
Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.
network
low complexity
uclouvain google debian CWE-415
6.5
2017-08-30 CVE-2016-10507 Integer Overflow or Wraparound vulnerability in Uclouvain Openjpeg
Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file.
network
low complexity
uclouvain CWE-190
6.5