VendorsJasper Projectjasperany version
Vulnerabilities

Jasper Project Jasper any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

52CVEs
CVE-2016-8882
The jpc_dec_tilefini function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
Published 2017-01-13 · Modified
5.5EPSS 0.016
CVE-2017-6851
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.
Published 2017-03-15 · Modified
5.5EPSS 0.015
CVE-2016-9395
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
Published 2017-03-23 · Modified
5.5EPSS 0.015
CVE-2016-8883
The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
Published 2017-01-13 · Modified
5.5EPSS 0.014
CVE-2016-9591
JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.
Published 2018-03-09 · Modified
5.5EPSS 0.014
CVE-2017-14232
The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted flif file.
Published 2019-08-15 · Modified
5.5EPSS 0.012
CVE-2021-26927
A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.
Published 2021-02-23 · Modified
5.5EPSS 0.011
CVE-2021-3443
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
Published 2021-03-25 · Modified
5.5EPSS 0.008
CVE-2021-27845
A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c
Published 2021-07-15 · Modified
5.5EPSS 0.007
CVE-2021-3467
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
Published 2021-03-25 · Modified
5.5EPSS 0.006
CVE-2025-8835
JasPer Image Color Space Conversion jas_image.c jas_image_chclrspc null pointer dereference
Published 2025-08-11 · Analyzed
5.5EPSS 0.002
CVE-2025-8836
JasPer JPEG2000 Encoder jpc_enc.c jpc_floorlog2 assertion
Published 2025-08-11 · Analyzed
3.3EPSS 0.002
← Prev2 / 2