CVE Tools

Independent-jpeg-group

13 CVEs tracked since 2017. Since Oct 2017, none of them reached CISA KEV.

Independent-jpeg-group CVEs per month

Oct 2017 to Oct 2021. Point at a month, or focus the strip and use the arrow keys.
Independent-jpeg-group CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-1020
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-0620
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-0630
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-1060

Products

The products that kept showing up in Independent-jpeg-group's monthly top three, with their CVEs summed over those months.

  1. Libjpeg-turbo83 months
  2. Libjpeg53 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Independent-jpeg-group.

  1. CVE-2021-29390libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.7.1
  2. CVE-2023-2804A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision...6.5
  3. CVE-2020-35538A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.5.5
  4. BDU:2021-05120Уязвимость функции tjInitDecompress() библиотеки для работы с изображениями libjpeg-turbo, позволяющая нарушителю оказать воздействие на доступность защищаемой информации3.7
  5. BDU:2021-05119Уязвимость функций alloc_large() и alloc_sarray() библиотеки для работы с изображениями libjpeg-turbo, позволяющая нарушителю вызвать операцию деления на ноль3.7
  6. BDU:2021-05122Уязвимость функции decode_mcu() библиотеки для работы с изображениями libjpeg-turbo, позволяющая нарушителю оказать воздействие на доступность защищаемой информации5.3
  7. BDU:2021-05123Уязвимость библиотеки для работы с изображениями libjpeg-turbo, позволяющая нарушителю оказать воздействие на доступность защищаемой информации3.7
  8. BDU:2021-05121Уязвимость функций decode_mcu() и decode_mcu_fast() библиотеки для работы с изображениями libjpeg-turbo, позволяющая нарушителю вызвать отказ в обслуживании5.9
  9. CVE-2021-37972Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.8.8
  10. CVE-2020-17541Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or deni...8.8
  11. CVE-2020-14152In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.7.1
  12. CVE-2020-14153In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.7.1
  13. CVE-2020-13790libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.8.1
  14. CVE-2019-2201In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged proc...7.8
  15. CVE-2018-14498get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-b...6.5

The record

Peak rank
#77 in Oct 2021
Busiest month shown
Oct 2021, 6 CVEs
Months with a KEV entry
0 since Oct 2017
Monthly snapshots
4 since 2017
Independent-jpeg-group's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store