Skip to main content

Vendor archive

uclouvain CVEs

Beta · best-effort

82 CVEs tagged to vendor uclouvain8 Critical, 27 High, 45 Medium, 2 Low, 0 Unrated.

CVE-2025-50952

Published Aug 7, 2025

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54874

Published Aug 5, 2025

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27814

Published Jan 26, 2021

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3182

Published Feb 20, 2020

The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8112

Published Jan 28, 2020

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6851

Published Jan 13, 2020

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

CVSS 7.5 · High

CVE-2018-20847

Published Jun 26, 2019

An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20846

Published Jun 26, 2019

Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20845

Published Jun 26, 2019

Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 82 CVEsPage 1 of 4