Jbig2dec

Vendor:

First CVE: Apr 17, 2017 · Active for 9 years

7
Total CVEs
More Total CVEs than 85% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jbig2dec over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2017
9 years ago
Most Recent CVE
Oct 31, 2023
1,001 days ago

CVE Severity & Scoring

Jbig2dec7 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local4 (57.1%)
Network3 (42.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (14.3%)
Unknown0 (0.0%)
Required6 (85.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_build_huffman_table function in jbig2_huffman.c during operat
Apr 19, 20177.826NONO
jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.
Apr 27, 20209.825NONO
libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig
May 24, 20176.524NONO
Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose function in jbig2_image.c during operations on a crafted .jb2
Apr 19, 20177.124NONO
Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from process memory, because of an i
Apr 17, 20177.124NONO
Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.
Oct 31, 20236.521NONO
ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halft
Apr 24, 20185.521NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Jbig2dec

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.2016.50.8%00
0.1347.02.2%00