Search CVE reports


Toggle filters

71 – 80 of 95 results


CVE-2016-8332

Medium priority
Fixed

A buffer overflow in OpenJPEG 2.1.1 causes arbitrary code execution when parsing a crafted image. An exploitable code execution vulnerability exists in the jpeg2000 image file format parser as implemented in the OpenJpeg library....

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg
openjpeg2
Show less packages

CVE-2016-7445

Low priority

Some fixes available 2 of 6

convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.

2 affected packages

openjpeg2, openjpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Not affected Not affected Not affected Not affected
openjpeg Not in release Not in release Not in release Not in release
Show less packages

CVE-2016-7163

Medium priority

Some fixes available 8 of 10

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Fixed
Show less packages

CVE-2015-8871

Medium priority

Some fixes available 1 of 5

Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2016-5159

Medium priority

Some fixes available 10 of 16

Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow)...

4 affected packages

openjpeg2, oxide-qt, chromium-browser, openjpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Not affected
oxide-qt Not in release
chromium-browser Fixed
openjpeg Not in release
Show less packages

CVE-2016-5158

Medium priority

Some fixes available 10 of 16

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a...

4 affected packages

oxide-qt, chromium-browser, openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
oxide-qt Not in release
chromium-browser Fixed
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2016-5139

Medium priority

Some fixes available 10 of 16

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or...

4 affected packages

openjpeg, openjpeg2, oxide-qt, chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
oxide-qt Not in release
chromium-browser Fixed
Show less packages

CVE-2016-1924

Low priority

Some fixes available 1 of 5

The opj_tgt_reset function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2016-1923

Low priority

Some fixes available 1 of 5

Heap-based buffer overflow in the opj_j2k_update_image_data function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release Not in release Not in release
openjpeg2 Not affected Not affected Not affected
Show less packages

CVE-2015-6581

Medium priority

Some fixes available 8 of 13

Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or...

3 affected packages

chromium-browser, openjpeg, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
openjpeg Not in release
oxide-qt Not in release
Show less packages