CVE-2020-6851High· 7.5▾ TwilightOpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.0%
— → 7.5
none → high
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
openjpeg <= 2.3.1fedora = 30fedora = 31debian_linux = 8.0debian_linux = 9.0debian_linux = 10.0enterprise_linux = 8.0enterprise_linux_desktop = 7.0enterprise_linux_eus = 7.7enterprise_linux_eus = 8.1enterprise_linux_eus = 8.2enterprise_linux_eus = 8.4enterprise_linux_server = 7.0enterprise_linux_server_aus = 7.7enterprise_linux_server_aus = 8.2enterprise_linux_server_aus = 8.4enterprise_linux_server_tus = 7.7enterprise_linux_server_tus = 8.2enterprise_linux_server_tus = 8.4enterprise_linux_workstation = 7.0georaster = 18coutside_in_technology = 8.5.4outside_in_technology = 8.5.5Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-39329Medium· 6.5A flaw was found in OpenJPEG
CVE-2023-39327Medium· 4.3A flaw was found in OpenJPEG
CVE-2026-19499High· 7.7Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path tha…
CVE-2026-28780Critical· 9.8Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker …
CVE-2026-14676High· 8.8Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants
CVE-2026-46655High· 7.8virtio-win provides Windows paravirtualized drivers for QEMU and KVM