CVE-2020-8175
MEDIUMjpeg-js <0.4.0 - DoS
Title source: llmDescription
Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.
Exploits (2)
Scores
CVSS v3
5.5
EPSS
0.0022
EPSS Percentile
44.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
Status
published
Products (2)
jpeg-js_project/jpeg-js
< 0.4.0
npm/jpeg-js
0 - 0.4.0npm
Published
Jul 24, 2020
Tracked Since
Feb 18, 2026