Metrics
Affected Vendors & Products
Fri, 26 Sep 2025 22:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized. | OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized. | 
Fri, 12 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:* | |
| Metrics | cvssV3_1 
 | cvssV3_1 
 | 
Wed, 06 Aug 2025 00:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | |
| Metrics | threat_severity 
 | cvssV3_1 
 
 | 
Tue, 05 Aug 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Uclouvain Uclouvain openjpeg | |
| Vendors & Products | Uclouvain Uclouvain openjpeg | 
Tue, 05 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 05 Aug 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized. | |
| Title | OpenJPEG allows OOB heap memory write in opj_jp2_read_header | |
| Weaknesses | CWE-457 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-05T14:33:17.323Z
Updated: 2025-09-26T21:55:42.071Z
Reserved: 2025-07-31T17:23:33.473Z
Link: CVE-2025-54874
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-08-05T14:48:30.244Z
 NVD
                        NVD
                    Status : Modified
Published: 2025-08-05T15:15:32.000
Modified: 2025-09-26T22:15:33.920
Link: CVE-2025-54874
 Redhat
                        Redhat