VendorsJPEGlibjpegall versions
Vulnerabilities

JPEG Libjpeg

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2022-37768
libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
Published 2022-08-18 · Modified
7.5EPSS 0.010
CVE-2022-31796
libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.
Published 2022-05-29 · Modified
6.5EPSS 0.009
CVE-2022-32978
There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.
Published 2022-06-10 · Modified
6.5EPSS 0.009
CVE-2021-39518
An issue was discovered in libjpeg through 2020021. LineBuffer::FetchRegion() in linebuffer.cpp has a heap-based buffer overflow.
Published 2021-09-20 · Modified
6.5EPSS 0.009
CVE-2021-39519
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PullQData() located in blockbitmaprequester.cpp It allows an attacker to cause Denial of Service.
Published 2021-09-20 · Modified
6.5EPSS 0.009
CVE-2021-39517
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::ReconstructUnsampled() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.
Published 2021-09-20 · Modified
6.5EPSS 0.009
CVE-2021-39515
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function SampleInterleavedLSScan::ParseMCU() located in sampleinterleavedlsscan.cpp. It allows an attacker to cause Denial of Service.
Published 2021-09-20 · Modified
6.5EPSS 0.009
CVE-2021-39520
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PushReconstructedData() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.
Published 2021-09-20 · Modified
6.5EPSS 0.009
CVE-2021-39514
An issue was discovered in libjpeg through 2020021. An uncaught floating point exception in the function ACLosslessScan::ParseMCU() located in aclosslessscan.cpp. It allows an attacker to cause Denial of Service.
Published 2021-09-20 · Modified
6.5EPSS 0.008
CVE-2021-39516
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function HuffmanDecoder::Get() located in huffmandecoder.hpp. It allows an attacker to cause Denial of Service.
Published 2021-09-20 · Modified
6.5EPSS 0.008
CVE-2022-37769
libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Published 2022-08-18 · Modified
6.5EPSS 0.007
CVE-2022-37770
libjpeg commit 281daa9 was discovered to contain a segmentation fault via LineMerger::GetNextLowpassLine at linemerger.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Published 2022-08-18 · Modified
6.5EPSS 0.007
CVE-2023-37836
libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Published 2023-07-13 · Modified
6.5EPSS 0.006
CVE-2023-37837
libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebitmaprequester.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Published 2023-07-13 · Modified
6.5EPSS 0.006
CVE-2022-35166
libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.
Published 2022-08-18 · Modified
5.5EPSS 0.003