Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25480
HistoryMay 26, 2020 - 2:22 a.m.

Denial Of Service (DoS)

2020-05-2602:22:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.001 Low

EPSS

Percentile

23.5%

jpeg-js is vulnerable to denial of service (DoS). The vulnerability exists as it fails to properly restrict the values of the resolution from the EXIF data, allowing a small manipulated image to cause a disproportionately large memory allocation.

CPENameOperatorVersion
jpeg-jsle0.3.7
jpeg-jsle0.3.7

0.001 Low

EPSS

Percentile

23.5%