← All CVEs

CVE-2014-8137

medium · 6.8

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.

6.8
CVSS
14.5%
EPSS (exploit prob.)
96th
EPSS percentile
2014-12-24
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
jasper_projectjasper<= 1.900.1
redhatenterprise_linux6.0
redhatenterprise_linux7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-8137