Kakadusoftware develops the Kakadu SDK, a software library for image compression and multimedia processing widely embedded in medical imaging, broadcasting, and archival systems. The sparse vulnerability record reflects the vendor's narrow product focus and clusters around memory-safety issues such as out-of-bounds writes and integer underflow, alongside path-traversal and file-upload weaknesses that arise in content-processing pipelines. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kakadusoftware over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5144HIGH An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a hea | Dec 12, 2019 | 8.8 | 28 | NO | NO |
CVE-2017-2812HIGH A code execution vulnerability exists in the kdu_buffered_expand function of the Kakadu SDK 7.9. A specially crafted JPEG 2000 file can be read by the program and can lead to an ou | Apr 24, 2018 | 7.8 | 21 | NO | NO |
CVE-2017-2811HIGH A code execution vulnerability exists in the Kakadu SDK 7.9's parsing of compressed JPEG 2000 images. A specially crafted JPEG 2000 file can be read by the program, and can lead to | Apr 24, 2018 | 7.8 | 21 | NO | NO |
CVE-2023-6562HIGH JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a | Dec 20, 2023 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kakadusoftware.
Media articles that mention a CVE ID that affects a product developed by Kakadusoftware — matched by CVE ID, not by vendor name.