Search CVE reports


Toggle filters

61 – 70 of 79 results


CVE-2016-7163

Medium priority

Some fixes available 8 of 10

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Fixed
Show less packages

CVE-2016-5159

Medium priority

Some fixes available 10 of 16

Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow)...

4 affected packages

openjpeg2, chromium-browser, openjpeg, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Not affected
chromium-browser Fixed
openjpeg Not in release
oxide-qt Not in release
Show less packages

CVE-2016-5158

Medium priority

Some fixes available 10 of 16

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a...

4 affected packages

oxide-qt, chromium-browser, openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
oxide-qt Not in release
chromium-browser Fixed
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2016-5139

Medium priority

Some fixes available 10 of 16

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or...

4 affected packages

openjpeg, openjpeg2, oxide-qt, chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
oxide-qt Not in release
chromium-browser Fixed
Show less packages

CVE-2016-4797

Medium priority

Some fixes available 1 of 2

Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of...

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
Show less packages

CVE-2016-4796

Medium priority
Ignored

Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg
openjpeg2
Show less packages

CVE-2016-3183

Medium priority

Some fixes available 1 of 2

The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.

2 affected packages

openjpeg2, openjpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2 Not affected
openjpeg Not in release
Show less packages

CVE-2016-3182

High priority
Ignored

The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.

2 affected packages

openjpeg2, openjpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2
openjpeg Not in release
Show less packages

CVE-2016-3181

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3182. Reason: This candidate is a duplicate of CVE-2016-3182. Notes: All CVE users should reference CVE-2016-3182 instead of this candidate. All references...

1 affected package

openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg2
Show less packages

CVE-2016-1924

Low priority

Some fixes available 1 of 5

The opj_tgt_reset function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.

2 affected packages

openjpeg, openjpeg2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openjpeg Not in release
openjpeg2 Not affected
Show less packages