Skip to main content

Vendor/product archive

dropbox / lepton CVEs

Beta · best-effort

6 CVEs tagged to dropbox / lepton0 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2022-26181

Published Feb 28, 2022

Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20820

Published Apr 23, 2019

read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20819

Published Apr 23, 2019

io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or po…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12108

Published Jun 11, 2018

An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application cra…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8891

Published May 10, 2017

Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7448

Published Apr 5, 2017

The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and appl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1