Known Vulnerabilities for products from Uclouvain

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Uclouvain".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-29338 Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This... 5.5 - MEDIUM 2021-04-14 2023-11-07
CVE-2021-3575 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.8 - HIGH 2022-03-04 2023-02-12
CVE-2020-27845 There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted in... 5.5 - MEDIUM 2021-01-05 2023-11-07
CVE-2020-27844 A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide craft... 7.8 - HIGH 2021-01-05 2023-11-07
CVE-2020-27843 A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to t... 5.5 - MEDIUM 2021-01-05 2023-11-07
CVE-2020-27842 There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be pr... 5.5 - MEDIUM 2021-01-05 2023-11-07
CVE-2020-27841 There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted in... 5.5 - MEDIUM 2021-01-05 2023-11-07
CVE-2020-27824 A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who ... 5.5 - MEDIUM 2021-05-13 2023-11-07
CVE-2020-27823 A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG... 7.8 - HIGH 2021-05-13 2023-11-07
CVE-2020-27814 A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to ca... 7.8 - HIGH 2021-01-26 2022-10-07
CVE-2020-15389 jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and inva... 6.5 - MEDIUM 2020-06-29 2022-10-06
CVE-2020-8112 opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmf... 8.8 - HIGH 2020-01-28 2023-11-07
CVE-2020-6851 OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of op... 7.5 - HIGH 2020-01-13 2023-11-07
CVE-2019-12973 In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could l... 5.5 - MEDIUM 2019-06-26 2022-10-05
CVE-2019-6988 An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memor... 6.5 - MEDIUM 2019-01-28 2020-08-24
CVE-2018-21010 OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c. 8.8 - HIGH 2019-09-05 2022-10-29
CVE-2018-20847 An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJ... 8.8 - HIGH 2019-06-26 2023-02-27
CVE-2018-20846 Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cpr... 6.5 - MEDIUM 2019-06-26 2023-02-27
CVE-2018-20845 Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG th... 6.5 - MEDIUM 2019-06-26 2023-02-27
CVE-2018-18088 OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c 6.5 - MEDIUM 2018-10-09 2019-08-21

Known software with vulnerabilities from Uclouvain

Type Vendor Product Version
ApplicationUclouvainOpenjpeg-