CVE-2018-20846: Uclouvain Openjpeg
Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
Affected products
- Uclouvain Openjpeg: up to and including 2.3.0
Published 2019-06-26. Last modified 2026-06-17.