← Vulnerability feed

Vulnerability record · CVE-2017-14164 · published 6 September 2017

CVE-2017-14164: Uclouvain openjpeg memory buffer overflow vulnerability

UUclouvain · Openjpeg

A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possibly remote code execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14152.

8.8 CVSS 3.1 High EPSS 5.4% · top 7.6% CWE-119 · Memory buffer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 6.8
5.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possibly remote code execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14152.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-14164 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-4289Uclouvain openjpeg vulnerabilityMultiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigg…EPSS 2.8%10.0CVE-2013-4290Uclouvain openjpeg memory buffer overflow vulnerabilityStack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified impact via unknown vectors to (1) lib/openjp3d/opj_j…EPSS 3.0%10.0CVE-2012-3358Uclouvain openjpeg memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (appli…EPSS 7.7%9.8CVE-2018-7648Uclouvain openjpeg memory buffer overflow vulnerabilityAn issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when…EPSS 1.6%9.8CVE-2017-17479Uclouvain openjpeg out-of-bounds write vulnerabilityIn OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-boun…EPSS 4.2%9.8CVE-2017-17480Uclouvain openjpeg out-of-bounds write vulnerabilityIn OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bou…EPSS 5.1%9.8CVE-2015-8871Debian linux use after free vulnerabilityUse-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact v…EPSS 3.0%9.3CVE-2012-1499Uclouvain openjpeg memory buffer overflow vulnerabilityThe JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of …EPSS 5.1%

Source: NIST National Vulnerability Database (record CVE-2017-14164), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.