IJG maintains libjpeg, a widely embedded image-processing library that, despite a narrow product scope, is distributed across countless server and client applications throughout the software ecosystem. The vendor's vulnerability profile centers on computational and parsing weaknesses inherent to JPEG decoding—including divide-by-zero conditions, excessive iteration, out-of-bounds reads, and uncontrolled resource consumption—that can affect any downstream product linking the library. Defenders should prioritize tracking libjpeg updates across their supply chain rather than monitoring IJG in isolation, since remediation typically flows through the vendors that ship the library; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ijg over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11813HIGH libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF. | Jun 6, 2018 | 7.5 | 26 | NO | NO |
CVE-2018-11212MEDIUM An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file. | May 16, 2018 | 6.5 | 24 | NO | NO |
CVE-2018-11214MEDIUM An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file. | May 16, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-11213MEDIUM An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file. | May 16, 2018 | 6.5 | 22 | NO | NO |
CVE-2020-14153HIGH In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers. | Jun 15, 2020 | 7.1 | 20 | NO | NO |
CVE-2020-14152HIGH In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption. | Jun 15, 2020 | 7.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ijg.
Media articles that mention a CVE ID that affects a product developed by Ijg — matched by CVE ID, not by vendor name.