
CVE-2013-6052 – openjpeg: out-of-bounds memory read flaws
https://notcve.org/view.php?id=CVE-2013-6052
04 Dec 2013 — OpenJPEG 1.3 and earlier allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read. OpenJPEG 1.3 y anteriores versiones permite a atacantes remotos obtener información sensible a través de vectores sin especificar. OpenJPEG is an open source library for reading and writing image files in JPEG 2000 format. Multiple heap-based buffer overflow flaws were found in OpenJPEG. An attacker could create a specially crafted OpenJPEG image that, when o... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2013-6054 – openjpeg: heap-based buffer overflows in version 1.3
https://notcve.org/view.php?id=CVE-2013-6054
04 Dec 2013 — Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045. Desbordamiento de búfer basado en memoria dinámica en OpenJPEG 1.3 tiene un impacto y vectores de ataque remotos no especificados, una vulnerabilidad diferente a CVE-2013-6045. OpenJPEG is an open source library for reading and writing image files in JPEG 2000 format. Multiple heap-based buffer overflow flaws were found in OpenJPEG. An attacker could create a specially crafted ... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-122: Heap-based Buffer Overflow •

CVE-2013-1447 – openjpeg: multiple denial of service flaws
https://notcve.org/view.php?id=CVE-2013-1447
04 Dec 2013 — OpenJPEG 1.3 and earlier allows remote attackers to cause a denial of service (memory consumption or crash) via unspecified vectors related to NULL pointer dereferences, division-by-zero, and other errors. OpenJPEG 1.3 y anteriores versiones permite a atacantes remotos provocar una denegación de servicio (consumo de memoria o caída) a través de vectores sin especificar. OpenJPEG is an open source library for reading and writing image files in JPEG 2000 format. Multiple heap-based buffer overflow flaws were ... • http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS •

CVE-2012-3535 – openjpeg: heap-based buffer overflow when decoding jpeg2000 files
https://notcve.org/view.php?id=CVE-2012-3535
05 Sep 2012 — Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted JPEG2000 file. Desbordamiento de búfer en OpenJPEG v1.5.0 y anteriores permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) y posiblemente ejecutar código arbitrario a través de un elaborado archivo JPEG2000. Multiple vulnerabilities in OpenJPEG could result in execution of arbitrary code. Versions... • http://code.google.com/p/openjpeg/issues/detail?id=170 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-122: Heap-based Buffer Overflow •

CVE-2012-3358 – openjpeg: heap-based buffer overflow when processing JPEG2000 image files
https://notcve.org/view.php?id=CVE-2012-3358
18 Jul 2012 — Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file. Múltiples desbordamientos de búfer basados memoria dínámica en la función j2k_read_sot en j2k.c en OpenJPEG v1.5, permite a atacantes remotos causar una denegación de servicio (caída de aplicación) y posiblemente ejecutar código arbitrar... • http://code.google.com/p/openjpeg/source/detail?r=1727 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-122: Heap-based Buffer Overflow •

CVE-2009-5030 – openjpeg: Heap memory corruption leading to invalid free by processing certain Gray16 TIFF images
https://notcve.org/view.php?id=CVE-2009-5030
18 Jul 2012 — The tcd_free_encode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted tile information in a Gray16 TIFF image, which causes insufficient memory to be allocated and leads to an "invalid free." La función tcd_free_encode tcd.c en OpenJPEG v1.3 a v1.5 permite a atacantes remotos causar una denegación de servicio (corrupción de memoria) y posiblemente ejecutar código arbitrario a través de la inf... • http://code.google.com/p/openjpeg/issues/detail?id=5 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-1499
https://notcve.org/view.php?id=CVE-2012-1499
11 Apr 2012 — The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of a JPEG image, which triggers memory corruption, aka "out-of heap-based buffer write." El codec JPEG 2000 en OpenJPEG anteriores a v1.5 no direcciona la memoria de forma correcta durante el análisis sintáctico, lo que provoca que atacantes remotos puedan ejecutar código a través de un fichero manipulado. • http://code.google.com/p/openjpeg/source/detail?r=1330 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •