CVE Tools

The-jasper-project

2 CVEs tracked since 2018. Since Aug 2018, none of them reached CISA KEV.

The-jasper-project CVEs per month

Aug 2018 to Aug 2018. Point at a month, or focus the strip and use the arrow keys.
The-jasper-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0820

Products

The products that kept showing up in The-jasper-project's monthly top three, with their CVEs summed over those months.

  1. Jasper21 month

Latest CVEs

The 9 most recently published vulnerabilities affecting The-jasper-project.

  1. CVE-2024-31744In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a spec...7.5
  2. CVE-2023-51257An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.7.8
  3. CVE-2018-20622JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.6.5
  4. CVE-2018-19540An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900...8.8
  5. CVE-2018-19541An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900...8.8
  6. CVE-2018-19542An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.6.5
  7. CVE-2016-9583An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.5.5
  8. CVE-2016-8654A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.7.8
  9. CVE-2016-9396The JPC_NOMINALGAIN function in jpc/jpc_t1cod.c in JasPer through 2.0.12 allows remote attackers to cause a denial of service (JPC_COX_RFT assertion failure) via unspecified vectors.7.5

The record

Peak rank
#197 in Aug 2018
Busiest month shown
Aug 2018, 2 CVEs
Months with a KEV entry
0 since Aug 2018
Monthly snapshots
1 since 2018
The-jasper-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store