
CVE-2012-3535 – openjpeg: heap-based buffer overflow when decoding jpeg2000 files
https://notcve.org/view.php?id=CVE-2012-3535
05 Sep 2012 — Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted JPEG2000 file. Desbordamiento de búfer en OpenJPEG v1.5.0 y anteriores permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) y posiblemente ejecutar código arbitrario a través de un elaborado archivo JPEG2000. Multiple vulnerabilities in OpenJPEG could result in execution of arbitrary code. Versions... • http://code.google.com/p/openjpeg/issues/detail?id=170 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-122: Heap-based Buffer Overflow •

CVE-2009-5030 – openjpeg: Heap memory corruption leading to invalid free by processing certain Gray16 TIFF images
https://notcve.org/view.php?id=CVE-2009-5030
18 Jul 2012 — The tcd_free_encode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted tile information in a Gray16 TIFF image, which causes insufficient memory to be allocated and leads to an "invalid free." La función tcd_free_encode tcd.c en OpenJPEG v1.3 a v1.5 permite a atacantes remotos causar una denegación de servicio (corrupción de memoria) y posiblemente ejecutar código arbitrario a través de la inf... • http://code.google.com/p/openjpeg/issues/detail?id=5 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-1499
https://notcve.org/view.php?id=CVE-2012-1499
11 Apr 2012 — The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of a JPEG image, which triggers memory corruption, aka "out-of heap-based buffer write." El codec JPEG 2000 en OpenJPEG anteriores a v1.5 no direcciona la memoria de forma correcta durante el análisis sintáctico, lo que provoca que atacantes remotos puedan ejecutar código a través de un fichero manipulado. • http://code.google.com/p/openjpeg/source/detail?r=1330 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •