Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libjpeg Turbo MEDIUM 6.5
CVE-2023-2804

A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability …

Patch available
Fix from $1,600 2023-05-25
Libjpeg Turbo MEDIUM 5.5
CVE-2020-35538

A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.

Patch available
Fix from $1,600 2022-08-31
Libjpeg Turbo MEDIUM 5.5
CVE-2021-46822

The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading…

Fix: after 2.0.90
Fix from $1,600 2022-06-18
Libjpeg Turbo HIGH 8.8
CVE-2020-17541

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the se…

Fix: 2.0.4+
Fix from $1,950 2021-06-01
Libjpeg Turbo HIGH 8.1
CVE-2020-13790

libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.

Patch available
Fix from $1,950 2020-06-03
Libjpeg Turbo MEDIUM 5.5
CVE-2019-13960

In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and he…

Patch available
Fix from $1,600 2019-07-18
Libjpeg Turbo HIGH 8.8
CVE-2018-20330

The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplic…

Patch available
Fix from $1,950 2018-12-21
Libjpeg Turbo MEDIUM 6.5
CVE-2018-19664

libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.

No fix yet
Fix from $1,600 2018-11-29
Libjpeg Turbo MEDIUM 6.5
CVE-2017-15232

libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.

Patch available
Fix from $1,600 2017-10-11