Rockcarry maintains a narrowly focused multimedia library, FFmpeg-derived JPEG handling code (FFJPEG), that despite limited product scope occupies a more prominent position in the landscape than its small vendor footprint might suggest, reflecting broad embedding in image-processing pipelines. The recurring vulnerability classes—out-of-bounds reads and writes, buffer overflows, NULL-pointer dereferences, and divide-by-zero conditions—are characteristic of C-based image parsers that must handle untrusted input across diverse format variants and edge cases. Defenders should inventory downstream products that bundle or link this library, as remediation often depends on integrating upstream fixes rather than patching the library in isolation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rockcarry over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24222HIGH Buffer Overflow vulnerability in jfif_decode() function in rockcarry ffjpeg through version 1.0.0, allows local attackers to execute arbitrary code due to an issue with ALIGN. | Aug 11, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-28471MEDIUM In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfi | May 5, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-45385MEDIUM A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the bmp is out of range, it returns without as | Feb 11, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-44957MEDIUM Global buffer overflow vulnerability exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23705. Issue is in the jfif_encode function at ffjpeg/src/jfif.c (line 708) could | Feb 8, 2022 | 6.5 | 22 | NO | NO |
CVE-2020-23705MEDIUM A global buffer overflow vulnerability in jfif_encode at jfif.c:701 of ffjpeg through 2020-06-22 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file. | Jul 15, 2021 | 6.5 | 22 | NO | NO |
CVE-2019-16351MEDIUM ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c. | Sep 16, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-16350MEDIUM ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c. | Sep 16, 2019 | 6.5 | 22 | NO | NO |
CVE-2018-16781MEDIUM ffjpeg.dll in ffjpeg before 2018-08-22 allows remote attackers to cause a denial of service (FPE signal) via a progressive JPEG file that lacks an AC Huffman table. | Sep 10, 2018 | 6.5 | 22 | NO | NO |
CVE-2019-16352MEDIUM ffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c. | Sep 16, 2019 | 6.5 | 21 | NO | NO |
CVE-2021-34122MEDIUM The function bitstr_tell at bitstr.c in ffjpeg commit 4ab404e has a NULL pointer dereference. | Mar 10, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rockcarry.
Media articles that mention a CVE ID that affects a product developed by Rockcarry — matched by CVE ID, not by vendor name.