Sploitus

CVE-2019-15145

No indexed exploits for CVE-2019-15145 yet

DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missing zero-bytes check in libdjvu/GBitmap.h.

Djvulibre Project Djvulibre
= 3.5.27
Fix
Available
CVSS 3.1
5.5 MEDIUM
EPSS
1.6% (73th percentile)
Weakness
CWE-125
NVD status
Modified
Published
2019-08-18
CVE-2019-15145 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2019-15145 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2019-15145 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.