The Jasper Project maintains a small, focused portfolio centered on image processing and document-handling libraries, tools that sit deep in the software supply chain and are embedded across a wide range of applications and server infrastructure. Despite the narrow product count, the vendor's prominence in the vulnerability landscape reflects the widespread deployment of these libraries—particularly the core Jasper image codec and related tools like HTTPdx—and the inherent complexity of parsing and rendering untrusted media formats. The vulnerability exposure recurs through memory-safety weakness classes including NULL-pointer dereferences, reachable assertions, buffer-boundary violations, out-of-bounds reads, and integer overflows, reflecting the low-level parsing and memory-management demands of a codec library. These weakness classes are characteristic of the attack surface presented by format parsers and have a durable track record of affecting downstream products through the supply chain. Defenders should inventory products that bundle Jasper rather than tracking the library alone, since remediation typically depends on downstream vendors rebuilding and releasing updates; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jasper Project over time
Signals from CVEs in this vendor scope (106 CVEs).
106 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3711HIGH Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a denial of service (crash) and possibly ex | Oct 16, 2009 | 10.0 | 77 | NO | YES |
CVE-2009-4769HIGH Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string spe | Apr 20, 2010 | 9.3 | 64 | NO | YES |
CVE-2009-3663HIGH Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code | Oct 11, 2009 | 10.0 | 42 | NO | YES |
CVE-2025-8837HIGH A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The man | Aug 11, 2025 | 7.8 | 30 | NO | NO |
CVE-2018-19541HIGH An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22 | Nov 26, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-19540HIGH An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22 | Nov 26, 2018 | 8.8 | 28 | NO | NO |
CVE-2014-8138HIGH Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code | Dec 24, 2014 | 7.5 | 27 | NO | NO |
CVE-2014-9029HIGH Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute | Dec 8, 2014 | 7.5 | 27 | NO | NO |
CVE-2018-19543HIGH An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c. | Nov 26, 2018 | 7.8 | 26 | NO | NO |
CVE-2016-8654HIGH A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected. | Aug 1, 2018 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (106 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jasper Project.
Media articles that mention a CVE ID that affects a product developed by Jasper Project — matched by CVE ID, not by vendor name.