Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jasper Project

First CVE: Oct 2, 2008Active for: 18 yearsTotal CVEs: 106
39.2
VTI Score
Medium

The Jasper Project maintains a small, focused portfolio centered on image processing and document-handling libraries, tools that sit deep in the software supply chain and are embedded across a wide range of applications and server infrastructure. Despite the narrow product count, the vendor's prominence in the vulnerability landscape reflects the widespread deployment of these libraries—particularly the core Jasper image codec and related tools like HTTPdx—and the inherent complexity of parsing and rendering untrusted media formats. The vulnerability exposure recurs through memory-safety weakness classes including NULL-pointer dereferences, reachable assertions, buffer-boundary violations, out-of-bounds reads, and integer overflows, reflecting the low-level parsing and memory-management demands of a codec library. These weakness classes are characteristic of the attack surface presented by format parsers and have a durable track record of affecting downstream products through the supply chain. Defenders should inventory products that bundle Jasper rather than tracking the library alone, since remediation typically depends on downstream vendors rebuilding and releasing updates; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
106
Total CVEs
More Total CVEs than 99% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jasper Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 2, 2008
17 years ago
Most Recent CVE
Aug 11, 2025
347 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (106 CVEs).

106 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-3711HIGH
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a denial of service (crash) and possibly ex
Oct 16, 200910.077NOYES
CVE-2009-4769HIGH
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string spe
Apr 20, 20109.364NOYES
CVE-2009-3663HIGH
Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code
Oct 11, 200910.042NOYES
CVE-2025-8837HIGH
A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The man
Aug 11, 20257.830NONO
CVE-2018-19541HIGH
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22
Nov 26, 20188.828NONO
CVE-2018-19540HIGH
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22
Nov 26, 20188.828NONO
CVE-2014-8138HIGH
Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code
Dec 24, 20147.527NONO
CVE-2014-9029HIGH
Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute
Dec 8, 20147.527NONO
CVE-2018-19543HIGH
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
Nov 26, 20187.826NONO
CVE-2016-8654HIGH
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
Aug 1, 20187.826NONO
View all 106 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products106 CVEs
54%
45%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local56 (52.8%)
Network35 (33.0%)
Unknown15 (14.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low91 (85.8%)
High0 (0.0%)
Unknown15 (14.2%)
User Interaction
None24 (22.6%)
Unknown15 (14.2%)
Required67 (63.2%)
Privileges Required
Low5 (4.7%)
High0 (0.0%)
None86 (81.1%)
Unknown15 (14.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (106 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.9% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
3.8% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jasper Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jasper Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jasper Project's Products

View all 5 CNAs →

Top CWEs