
CVE-2016-1924 – Gentoo Linux Security Advisory 201612-26
https://notcve.org/view.php?id=CVE-2016-1924
27 Jan 2016 — The opj_tgt_reset function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image. La función opj_tgt_reset en OpenJpeg 2016.1.18 permite a atacantes remotos causar una denegación de servicio (lectura fuera de rango y caída de aplicación) a través de una imagen JPEG 2000 manipulada. Multiple vulnerabilities have been found in OpenJPEG, the worst of which may allow execution of arbitrary code. Versions less than 2.1.... • http://www.debian.org/security/2016/dsa-3665 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-4289 – Gentoo Linux Security Advisory 201412-24
https://notcve.org/view.php?id=CVE-2013-4289
18 Apr 2014 — Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigger a heap-based buffer overflow. Múltiples desbordamientos de entero en lib/openjp3d/jp3d.c en OpenJPEG en versiones anteriores a 1.5.2 permiten a atacantes remotos tener impacto y vectores no especificados, lo que desencadena un desbordamiento de búfer basado en memoria dinámica. Multiple vulnerabilities have been found in OpenJPEG, the worst of which may resu... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS • CWE-189: Numeric Errors •

CVE-2013-4290 – Gentoo Linux Security Advisory 201412-24
https://notcve.org/view.php?id=CVE-2013-4290
18 Apr 2014 — Stack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified impact via unknown vectors to (1) lib/openjp3d/opj_jp3d_compress.c, (2) bin/jp3d/convert.c, or (3) lib/openjp3d/event.c. Desbordamiento de buffer basado en pila en OpenJPEG en versiones anteriores a 1.5.2 permite a atacantes remotos tener un impacto no especificado a través de vectores desconocidos en (1) lib/openjp3d/opj_jp3d_compress.c, (2) bin/jp3d/convert.c o (3) lib/openjp3d/event.c. Multiple vulnerabilitie... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-6053 – Gentoo Linux Security Advisory 201412-24
https://notcve.org/view.php?id=CVE-2013-6053
18 Jan 2014 — OpenJPEG 1.5.1 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read. OpenJPEG 1.5.1 permite a atacantes remotos obtener información sensible a través de vectores no especificados que provocan una lectura basada en memoria dinámica fuera de rango. Multiple heap-based buffer overflow flaws were found in OpenJPEG. An attacker could create a specially crafted OpenJPEG image that, when opened, could cause an application using openjpeg to cra... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS • CWE-20: Improper Input Validation •

CVE-2013-6887 – Gentoo Linux Security Advisory 201412-24
https://notcve.org/view.php?id=CVE-2013-6887
18 Jan 2014 — OpenJPEG 1.5.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger NULL pointer dereferences, division-by-zero, and other errors. OpenJPEG 1.5.1 permite a atacantes remotos causar una denegación de servicio a través de vectores no especificados que provocan referencias a puntero nulo, división-por-cero (division-by-zero) y otros errores. Multiple heap-based buffer overflow flaws were found in OpenJPEG. An attacker could create a specially crafted OpenJPEG image that, wh... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS • CWE-20: Improper Input Validation •

CVE-2013-6045 – openjpeg: heap-based buffer overflows
https://notcve.org/view.php?id=CVE-2013-6045
04 Dec 2013 — Multiple heap-based buffer overflows in OpenJPEG 1.3 and earlier might allow remote attackers to execute arbitrary code via unspecified vectors. Múltiples desbodamientos de búfer basados en memoria dinámica en OpenJPEG 1.3 y anteriores podría permitir a atacantes remotos ejecutar código arbitrario a través de vectores no especificados. OpenJPEG is an open source library for reading and writing image files in JPEG 2000 format. Multiple heap-based buffer overflow flaws were found in OpenJPEG. An attacker coul... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-122: Heap-based Buffer Overflow •

CVE-2013-6052 – openjpeg: out-of-bounds memory read flaws
https://notcve.org/view.php?id=CVE-2013-6052
04 Dec 2013 — OpenJPEG 1.3 and earlier allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read. OpenJPEG 1.3 y anteriores versiones permite a atacantes remotos obtener información sensible a través de vectores sin especificar. OpenJPEG is an open source library for reading and writing image files in JPEG 2000 format. Multiple heap-based buffer overflow flaws were found in OpenJPEG. An attacker could create a specially crafted OpenJPEG image that, when o... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2013-6054 – openjpeg: heap-based buffer overflows in version 1.3
https://notcve.org/view.php?id=CVE-2013-6054
04 Dec 2013 — Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045. Desbordamiento de búfer basado en memoria dinámica en OpenJPEG 1.3 tiene un impacto y vectores de ataque remotos no especificados, una vulnerabilidad diferente a CVE-2013-6045. OpenJPEG is an open source library for reading and writing image files in JPEG 2000 format. Multiple heap-based buffer overflow flaws were found in OpenJPEG. An attacker could create a specially crafted ... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-122: Heap-based Buffer Overflow •

CVE-2013-1447 – openjpeg: multiple denial of service flaws
https://notcve.org/view.php?id=CVE-2013-1447
04 Dec 2013 — OpenJPEG 1.3 and earlier allows remote attackers to cause a denial of service (memory consumption or crash) via unspecified vectors related to NULL pointer dereferences, division-by-zero, and other errors. OpenJPEG 1.3 y anteriores versiones permite a atacantes remotos provocar una denegación de servicio (consumo de memoria o caída) a través de vectores sin especificar. OpenJPEG is an open source library for reading and writing image files in JPEG 2000 format. Multiple heap-based buffer overflow flaws were ... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS •

CVE-2012-3535 – openjpeg: heap-based buffer overflow when decoding jpeg2000 files
https://notcve.org/view.php?id=CVE-2012-3535
05 Sep 2012 — Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted JPEG2000 file. Desbordamiento de búfer en OpenJPEG v1.5.0 y anteriores permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) y posiblemente ejecutar código arbitrario a través de un elaborado archivo JPEG2000. Multiple vulnerabilities in OpenJPEG could result in execution of arbitrary code. Versions... • http://code.google.com/p/openjpeg/issues/detail?id=170 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-122: Heap-based Buffer Overflow •