Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ijg

First CVE: May 16, 2018Active for: 8 yearsTotal CVEs: 6

IJG maintains libjpeg, a widely embedded image-processing library that, despite a narrow product scope, is distributed across countless server and client applications throughout the software ecosystem. The vendor's vulnerability profile centers on computational and parsing weaknesses inherent to JPEG decoding—including divide-by-zero conditions, excessive iteration, out-of-bounds reads, and uncontrolled resource consumption—that can affect any downstream product linking the library. Defenders should prioritize tracking libjpeg updates across their supply chain rather than monitoring IJG in isolation, since remediation typically flows through the vendors that ship the library; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ijg over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2018
8 years ago
Most Recent CVE
Jun 15, 2020
2,230 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-11813HIGH
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
Jun 6, 20187.526NONO
CVE-2018-11212MEDIUM
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
May 16, 20186.524NONO
CVE-2018-11214MEDIUM
An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
May 16, 20186.522NONO
CVE-2018-11213MEDIUM
An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
May 16, 20186.522NONO
CVE-2020-14153HIGH
In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.
Jun 15, 20207.120NONO
CVE-2020-14152HIGH
In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.
Jun 15, 20207.120NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (33.3%)
Network4 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (16.7%)
Unknown0 (0.0%)
Required5 (83.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ijg.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ijg — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ijg's Products

View all 1 CNAs →

Top CWEs