AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-8363

MEDIUM · CVSS 6.8 EPSS 2.07%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-11-26 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.8. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2015-8363
Severity
MEDIUM
CVSS
6.8
EPSS
2.07%

Original NVD Description

The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not enforce uniqueness of the SIZ marker in a JPEG 2000 image, which allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via a crafted image with two or more of these markers.