Jbig2dec
Vendor:
First CVE: Apr 17, 2017 · Active for 9 years
7
Total CVEs
More Total CVEs than 85% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jbig2dec over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2017
9 years ago
Most Recent CVE
Oct 31, 2023
1,001 days ago
CVE Severity & Scoring
Jbig2dec7 CVEs
43%
43%
14%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (57.1%)
Network3 (42.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (14.3%)
Unknown0 (0.0%)
Required6 (85.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7975HIGH Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_build_huffman_table function in jbig2_huffman.c during operat | Apr 19, 2017 | 7.8 | 26 | NO | NO |
CVE-2020-12268CRITICAL jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow. | Apr 27, 2020 | 9.8 | 25 | NO | NO |
CVE-2017-9216MEDIUM libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig | May 24, 2017 | 6.5 | 24 | NO | NO |
CVE-2017-7976HIGH Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose function in jbig2_image.c during operations on a crafted .jb2 | Apr 19, 2017 | 7.1 | 24 | NO | NO |
CVE-2017-7885HIGH Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from process memory, because of an i | Apr 17, 2017 | 7.1 | 24 | NO | NO |
CVE-2023-46361MEDIUM Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c. | Oct 31, 2023 | 6.5 | 21 | NO | NO |
CVE-2016-9601MEDIUM ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halft | Apr 24, 2018 | 5.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Jbig2dec
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.20 | 1 | 6.5 | 0.8% | 0 | 0 |
| 0.13 | 4 | 7.0 | 2.2% | 0 | 0 |