VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 38 minutes ago
Reset
More filters (1)
Columns
Oracle product: Oracle Communications / Platform (JasPer)
Overview 2 matches · 0 in RASP scope · 0 protected · 0 KEV · 0 public PoC · 1 CISA SSVC · 0 EPSS ≥ 0.5 · 0 disputed
2matches 0in RASP scope0.0% 0protected0.0% 0KEV0.0% 0public PoC0.0% 1CISA SSVC50.0% 0EPSS ≥ 0.50.0% 0disputed0.0%
Critical 0 0.0% High 1 50.0% Medium 0 0.0% Low 1 50.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 2 100.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 0 0.0% not blocked 2 100.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 0 0.0% Proof of concept only 1 50.0% Forecast only 0 0.0% No public exploit 1 50.0%
split by peak 1 / month
Unknown: 0None: 0Low: 1Medium: 0High: 1Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 2Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 2blocked by ARMR today: 0 No public exploit: 1Forecast only: 0Proof of concept only: 1Working exploit published: 0Exploited in the wild: 0 April 2024: 1 CVE May 2024: 0 CVEs June 2024: 0 CVEs July 2024: 0 CVEs August 2024: 0 CVEs September 2024: 0 CVEs October 2024: 0 CVEs November 2024: 0 CVEs December 2024: 0 CVEs January 2025: 0 CVEs February 2025: 0 CVEs March 2025: 0 CVEs April 2025: 0 CVEs May 2025: 0 CVEs June 2025: 0 CVEs July 2025: 0 CVEs August 2025: 1 CVE
Apr 24Jun 24Aug 24Oct 24Dec 24Feb 25Apr 25Jun 25Aug 25
2 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2025-8837 Low 2025-08-11 Not applicable Proof of concept only A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named 8308060d3fbc1da10353ac8a95c8ea60eba9c25a. It is recommended to apply a patch to fix this issue.
CVE-2024-31744 High 2024-04-19 Not applicable No public exploit In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.