← Back

Openjpeg

openjpeg

Vendor: Uclouvain • 82 CVEs

CVEs (82)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Uclouvain
1Openjpeg
May 13, 2026
Dec 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote...Show more
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.Show less
3Debian
GoogleUclouvain
3Debian Linux
OpenjpegPdfium
May 13, 2026
Oct 18, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.
1Uclouvain
1Openjpeg
May 13, 2026
Sep 6, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow...Show more
A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possibly remote code execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14152.Show less
2Debian
Uclouvain
2Debian Linux
Openjpeg
May 13, 2026
Sep 5, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffe...Show more
A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c and opj_j2k_write_sot in lib/openjp2/j2k.c) or possibly remote code execution.Show less
2Debian
Uclouvain
2Debian Linux
Openjpeg
May 13, 2026
Sep 5, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based b...Show more
An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_mqc_flush in lib/openjp2/mqc.c and opj_t1_encode_cblk in lib/openjp2/t1.c) or possibly remote code execution.Show less
2Debian
Uclouvain
2Debian Linux
Openjpeg
May 13, 2026
Aug 30, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remo...Show more
A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.Show less
2Debian
Uclouvain
2Debian Linux
Openjpeg
May 13, 2026
Aug 30, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact.
2Debian
Uclouvain
2Debian Linux
Openjpeg
May 13, 2026
Aug 30, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possi...Show more
A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.Show less
1Uclouvain
1Openjpeg
May 13, 2026
Aug 30, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted...Show more
Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file.Show less
1Uclouvain
1Openjpeg
May 13, 2026
Aug 30, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via craf...Show more
Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.Show less
1Uclouvain
1Openjpeg
May 13, 2026
Aug 30, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2....Show more
NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.Show less
1Uclouvain
1Openjpeg
May 13, 2026
Aug 30, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file.
1Uclouvain
1Openjpeg
May 13, 2026
Aug 21, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the op...Show more
The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c.Show less
2Fedoraproject
Uclouvain
2Fedora
Openjpeg
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists be...Show more
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.Show less
2Fedoraproject
Uclouvain
2Fedora
Openjpeg
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.
1Uclouvain
1Openjpeg
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.
2Redhat
Uclouvain
5Enterprise Linux
Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Big Endian+2 more
May 6, 2026
Dec 22, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.
1Uclouvain
1Openjpeg
May 6, 2026
Oct 30, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
1Uclouvain
1Openjpeg
May 6, 2026
Oct 30, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
1Uclouvain
1Openjpeg
May 6, 2026
Oct 30, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.