Search CVE reports


Toggle filters

71 – 80 of 95 results


CVE-2016-1923

Low priority

Some fixes available 1 of 5

Heap-based buffer overflow in the opj_j2k_update_image_data function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release Not in release Not in release
openjpeg2 Not affected Not affected Not affected
Show less packages

CVE-2016-10507

Medium priority

Some fixes available 1 of 3

Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file.

2 affected packages

openjpeg2, openjpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Not affected
openjpeg Not in release
Show less packages

CVE-2016-10506

Medium priority

Some fixes available 2 of 5

Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.

3 affected packages

openjpeg, openjpeg2, ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release Not in release Not in release Not in release
openjpeg2 Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-10505

Medium priority
Ignored

NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow...

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2016-10504

Medium priority

Some fixes available 2 of 3

Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2015-8871

Medium priority

Some fixes available 1 of 5

Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2015-6581

Medium priority

Some fixes available 8 of 13

Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or...

3 affected packages

chromium-browser, openjpeg, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
openjpeg Not in release
oxide-qt Not in release
Show less packages

CVE-2015-1273

Medium priority

Some fixes available 22 of 30

Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid...

3 affected packages

openjpeg, chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release Not in release Not in release Not in release
chromium-browser Fixed Fixed Fixed Fixed
oxide-qt Not in release Not in release Not in release Not in release
Show less packages

CVE-2015-1239

Medium priority
Fixed

Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.

2 affected packages

openjpeg2, openjpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Not affected Not affected Not affected
openjpeg Not in release Not in release Not in release
Show less packages

CVE-2014-7947

Medium priority

Some fixes available 24 of 50

OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c.

7 affected packages

insighttoolkit4, oxide-qt, vxl, chromium-browser, openjpeg...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
insighttoolkit4 Not in release Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release
vxl Not in release Not in release Not in release Not in release
chromium-browser Fixed Fixed Fixed Fixed
openjpeg Not in release Not in release Not in release Not in release
openjpeg2 Not affected Not affected Not affected Not affected
gdcm Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages