Uclouvain maintains OpenJPEG, a widely embedded JPEG 2000 codec library that sits deep in the software supply chain across media processing, document handling, and imaging applications. Despite a narrow product portfolio, the library's prevalence in downstream software means a single vulnerability can propagate broadly, and the vendor's disclosures concentrate on memory-safety and input-handling weaknesses—including out-of-bounds writes, buffer boundary violations, NULL pointer dereferences, and integer overflows—that are characteristic of image parsing code. A meaningful share of the vendor's vulnerabilities reach critical severity, reflecting the parser's role in consuming untrusted image data from potentially hostile sources. Defenders should treat OpenJPEG flaws as supply-chain issues requiring inventory of dependent applications and coordinated remediation across those products rather than tracking the library in isolation. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uclouvain over time
Signals from CVEs in this vendor scope (82 CVEs).
82 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10504MEDIUM Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) | Aug 30, 2017 | 6.5 | 35 | NO | YES |
CVE-2012-3358HIGH Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly exec | Jul 18, 2012 | 10.0 | 33 | NO | NO |
CVE-2025-54874CRITICAL OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is t | Aug 5, 2025 | 9.8 | 32 | NO | NO |
CVE-2017-17480CRITICAL In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to re | Dec 8, 2017 | 9.8 | 32 | NO | NO |
CVE-2018-7648CRITICAL An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or | Mar 2, 2018 | 9.8 | 31 | NO | NO |
CVE-2017-17479CRITICAL In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to rem | Dec 8, 2017 | 9.8 | 31 | NO | NO |
CVE-2012-1499HIGH The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of a JPEG image, which triggers me | Apr 11, 2012 | 9.3 | 31 | NO | NO |
CVE-2017-14152HIGH A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to re | Sep 5, 2017 | 8.8 | 30 | NO | NO |
CVE-2017-14041HIGH A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to r | Aug 30, 2017 | 8.8 | 30 | NO | NO |
CVE-2017-14040HIGH An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service | Aug 30, 2017 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (82 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uclouvain.
Media articles that mention a CVE ID that affects a product developed by Uclouvain — matched by CVE ID, not by vendor name.