CVE Tools

Jasper

103 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Jasper, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Jasper CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Jasper CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-083
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 103 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical22%
  • High4140%
  • Medium5856%
  • Low22%

Latest CVEs

The 15 most recently published vulnerabilities affecting Jasper.

  1. CVE-2025-8837JasPer JPEG2000 File jpc_dec.c jpc_dec_dump use after free5.3
  2. CVE-2025-8836JasPer JPEG2000 Encoder jpc_enc.c jpc_floorlog2 assertion3.3
  3. CVE-2025-8835JasPer Image Color Space Conversion jas_image.c jas_image_chclrspc null pointer dereference3.3
  4. CVE-2024-31744In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a spec...7.5
  5. CVE-2023-51257An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.7.8
  6. CVE-2022-2963A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.7.5
  7. CVE-2022-40755JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.5.5
  8. CVE-2021-27845A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c5.5
  9. CVE-2021-3467A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could...5.5
  10. CVE-2021-3443A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an ap...5.5
  11. CVE-2021-26927A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.5.5
  12. CVE-2021-26926A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.7.1
  13. CVE-2021-3272jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.5.5
  14. CVE-2020-27828There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data ...7.8
  15. CVE-2015-8751Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memor...8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store