Lepton is a focused image-compression library that, despite a narrow product scope, sees deployment across diverse applications and systems where its codec is embedded. The recurring vulnerability signal centers on memory-safety and input-handling issues including out-of-bounds reads and writes, improper input validation, and infinite-loop conditions, which are characteristic of native codec implementations that parse untrusted image data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lepton Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4104MEDIUM A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compression tool, resulting in a denial-of-service. | Nov 28, 2022 | 5.5 | 21 | NO | NO |
CVE-2016-6237MEDIUM The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file. | Feb 2, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-6234MEDIUM The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file. | Feb 2, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-6238MEDIUM The write_ujpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds read) via a crafted jpeg file. | Feb 2, 2017 | 5.5 | 20 | NO | NO |
CVE-2016-6236MEDIUM The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file. | Feb 2, 2017 | 5.5 | 16 | NO | NO |
CVE-2016-6235MEDIUM The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file. | Feb 2, 2017 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lepton Project.
Media articles that mention a CVE ID that affects a product developed by Lepton Project — matched by CVE ID, not by vendor name.