Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

21 – 30 of 30 results


CVE-2018-11813

Low priority

Some fixes available 6 of 22

libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

3 affected packages

libjpeg-turbo, libjpeg6b, libjpeg9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libjpeg-turbo Not affected Not affected Not affected Fixed Fixed
libjpeg6b Vulnerable Vulnerable Vulnerable Vulnerable Fixed
libjpeg9 Not affected Not affected Not affected Vulnerable Fixed
Show less packages

CVE-2018-11214

Low priority

Some fixes available 4 of 21

An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

3 affected packages

libjpeg-turbo, libjpeg6b, libjpeg9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libjpeg-turbo Not affected Not affected Not affected Not affected Not affected
libjpeg6b Vulnerable Vulnerable Vulnerable Vulnerable Fixed
libjpeg9 Not affected Not affected Not affected Vulnerable Fixed
Show less packages

CVE-2018-11213

Low priority

Some fixes available 4 of 21

An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

3 affected packages

libjpeg-turbo, libjpeg6b, libjpeg9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libjpeg-turbo Not affected Not affected Not affected Not affected Not affected
libjpeg6b Vulnerable Vulnerable Vulnerable Vulnerable Fixed
libjpeg9 Not affected Not affected Not affected Vulnerable Fixed
Show less packages

CVE-2018-11212

Low priority

Some fixes available 4 of 21

An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.

3 affected packages

libjpeg-turbo, libjpeg6b, libjpeg9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libjpeg-turbo Not affected Not affected Not affected Not affected Not affected
libjpeg6b Vulnerable Vulnerable Vulnerable Vulnerable Fixed
libjpeg9 Not affected Not affected Not affected Vulnerable Fixed
Show less packages

CVE-2018-10126

Low priority
Needs evaluation

LibTIFF 4.0.9 has a NULL pointer dereference in the jpeg_fdct_16x16 function in jfdctint.c.

4 affected packages

libjpeg-turbo, libjpeg6b, libjpeg9, tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libjpeg-turbo Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libjpeg6b Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libjpeg9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tiff Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-3616

Low priority

Some fixes available 3 of 8

The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.

3 affected packages

libjpeg-turbo, libjpeg6b, libjpeg9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libjpeg-turbo Not affected Not affected Not affected Not affected
libjpeg6b Not affected Not affected Not affected Not affected
libjpeg9 Not affected Not affected Fixed Fixed
Show less packages

CVE-2016-6702

Medium priority
Ignored

A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an...

6 affected packages

android, chromium-browser, libjpeg-turbo, libjpeg6b, libjpeg9, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
android Not in release Ignored
chromium-browser Ignored Ignored
libjpeg-turbo Not affected Not affected
libjpeg6b Not affected Not affected
libjpeg9 Not affected Not affected
oxide-qt Not in release Ignored
Show less packages

CVE-2013-6630

Medium priority

Some fixes available 17 of 19

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that...

4 affected packages

firefox, libjpeg-turbo, libjpeg6b, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
firefox
libjpeg-turbo
libjpeg6b
thunderbird
Show less packages

CVE-2013-6629

Medium priority

Some fixes available 17 of 22

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data...

5 affected packages

firefox, libjpeg-turbo, libjpeg6b, openjdk-7, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
firefox
libjpeg-turbo
libjpeg6b
openjdk-7
thunderbird
Show less packages

CVE-2006-3005

Unknown priority
Not affected

The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that...

1 affected packages

libjpeg6b

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libjpeg6b
Show less packages