Search CVE reports


Toggle filters

51 – 60 of 79 results


CVE-2017-14040

Medium priority

Some fixes available 6 of 7

An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact.

2 affected packages

openjpeg2, openjpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Fixed
openjpeg Not in release
Show less packages

CVE-2017-14039

Medium priority

Some fixes available 6 of 7

A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or...

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Fixed
Show less packages

CVE-2016-10507

Medium priority

Some fixes available 1 of 3

Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file.

2 affected packages

openjpeg2, openjpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Not affected
openjpeg Not in release
Show less packages

CVE-2016-10506

Medium priority

Some fixes available 2 of 5

Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.

3 affected packages

ghostscript, openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Not affected Not affected Not affected Not affected
openjpeg Not in release Not in release Not in release Not in release
openjpeg2 Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-10505

Medium priority
Ignored

NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow...

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2016-10504

Medium priority

Some fixes available 2 of 3

Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2017-12982

Low priority

Some fixes available 2 of 5

The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in...

3 affected packages

ghostscript, openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Not affected Not affected Not affected
openjpeg Not in release Not in release Not in release
openjpeg2 Not affected Not affected Fixed
Show less packages

CVE-2016-4797

Medium priority

Some fixes available 1 of 2

Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of...

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2016-4796

Medium priority
Ignored

Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg
openjpeg2
Show less packages

CVE-2016-3183

Medium priority

Some fixes available 1 of 2

The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.

2 affected packages

openjpeg2, openjpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Not affected
openjpeg Not in release
Show less packages