CVE-2016-9262: Jasper Project Jasper
Medium severity, CVSS 5.5. EPSS: 1.7% chance of exploitation in the next 30 days.
Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.
Affected products
- Jasper Project Jasper: up to and including 1.900.21
Published 2017-03-23. Last modified 2026-06-17.