CVE-2016-9113: Uclouvain Openjpeg
High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.
There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.
Affected products
- Uclouvain Openjpeg: version 2.1.2 only
Published 2016-10-30. Last modified 2026-06-17.