← Vulnerability feed

Vulnerability record · CVE-2012-3358 · published 18 July 2012

CVE-2012-3358: Uclouvain openjpeg memory buffer overflow vulnerability

UUclouvain · Openjpeg

Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file.

10.0 CVSS 2.0 High EPSS 7.7% · top 5.6% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
7.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-3358 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-4289Uclouvain openjpeg vulnerabilityMultiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigg…EPSS 2.8%10.0CVE-2013-4290Uclouvain openjpeg memory buffer overflow vulnerabilityStack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified impact via unknown vectors to (1) lib/openjp3d/opj_j…EPSS 3.0%9.8CVE-2018-7648Uclouvain openjpeg memory buffer overflow vulnerabilityAn issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when…EPSS 1.6%9.8CVE-2017-17479Uclouvain openjpeg out-of-bounds write vulnerabilityIn OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-boun…EPSS 4.2%9.8CVE-2017-17480Uclouvain openjpeg out-of-bounds write vulnerabilityIn OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bou…EPSS 5.1%9.8CVE-2015-8871Debian linux use after free vulnerabilityUse-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact v…EPSS 3.0%9.3CVE-2012-1499Uclouvain openjpeg memory buffer overflow vulnerabilityThe JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of …EPSS 5.1%8.8CVE-2020-8112Uclouvain openjpeg out-of-bounds write vulnerabilityopj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different…EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2012-3358), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.