CVE-2012-3358: Uclouvain Openjpeg
High severity, CVSS 10.0. EPSS: 7.7% chance of exploitation in the next 30 days.
Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file.
Affected products
- Uclouvain Openjpeg: version 1.5 only
Published 2012-07-18. Last modified 2026-06-16.