Libjpeg is a widely embedded image-processing library whose modest disclosure volume belies its prevalence across applications, servers, and embedded systems that handle JPEG decoding; vulnerabilities in this library can propagate downstream to every product that links it. The recurring weakness classes center on memory-safety issues such as NULL-pointer dereferences and reachable assertions, reflecting the parsing complexity inherent to image codec implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libjpeg Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32202MEDIUM In libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp. | Jun 2, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-32201MEDIUM In libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp. | Jun 2, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-31620MEDIUM In libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-bounds array access during arith | May 25, 2022 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libjpeg Project.
Media articles that mention a CVE ID that affects a product developed by Libjpeg Project — matched by CVE ID, not by vendor name.