Jasper

Vendor:

First CVE: Oct 2, 2008 · Active for 17 years

101
Total CVEs
More Total CVEs than 99% of tracked products
7.8
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jasper over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 2, 2008
17 years ago
Most Recent CVE
Aug 11, 2025
349 days ago

CVE Severity & Scoring

Jasper101 CVEs
All CVEs352,719 CVEs
LowMediumHigh
Attack Vector
Local56 (55.4%)
Network35 (34.7%)
Unknown10 (9.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low91 (90.1%)
High0 (0.0%)
Unknown10 (9.9%)
User Interaction
None24 (23.8%)
Unknown10 (9.9%)
Required67 (66.3%)
Privileges Required
Low5 (5.0%)
High0 (0.0%)
None86 (85.1%)
Unknown10 (9.9%)

Top CVEs

Signals from CVEs in this product scope (101 CVEs).

101 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The man
Aug 11, 20257.830NONO
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22
Nov 26, 20188.828NONO
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22
Nov 26, 20188.828NONO
Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code
Dec 24, 20147.527NONO
Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute
Dec 8, 20147.527NONO
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
Nov 26, 20187.826NONO
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
Aug 1, 20187.826NONO
There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
Aug 29, 20177.526NONO
There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
Aug 29, 20177.526NONO
There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack.
Aug 29, 20177.526NONO

Exploit Exposure

Signals from CVEs in this product scope (101 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (101 CVEs).

Media Mentions

Signals from CVEs in this product scope (101 CVEs).

Top CNAs Publishing CVEs For Jasper

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0.626.50.8%00
2.0.2415.51.1%00
2.0.14136.82.2%00
2.0.1327.02.6%00
2.0.12107.33.6%00
1.900.515.52.3%00
1.900.2725.51.9%00
1.900.2217.53.8%00
1.900.1785.51.5%00
1.900.1317.53.6%00
1.900.187.66.6%00