VDB
CVE-2018-10126
CVE-2018-10126
PUBLISHED
ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.
EPSS 0.64% · 71.0th percentile
Risk Scores
EPSS Score
0.64%
71.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | libjpeg6b | 0, 1:6b2-3 |
| Ubuntu:18.04:LTS | libjpeg6b | 0, 1:6b2-3 |
| Ubuntu:18.04:LTS | libjpeg9 | 0, 1:9b-2 |
| Ubuntu:Pro:14.04:LTS | libjpeg6b | 6b1-4ubuntu1, *, 6b1-4ubuntu1+esm1 |
| Ubuntu:22.04:LTS | libjpeg9 | 1:9d-1, 0 |
| Ubuntu:22.04:LTS | libjpeg-turbo | 2.0.6-0ubuntu2, 0, 2.0.6-0ubuntu3 |
| Ubuntu:24.04:LTS | libjpeg9 | 0, 1:9e-1build1, 1:9e-1 |
| Ubuntu:24.04:LTS | libjpeg6b | 0, 1:6b2-3.1 |
| Ubuntu:25.10 | libjpeg9 | 0, 1:9f-2 |
| Ubuntu:24.04:LTS | libjpeg-turbo | 2.1.5-2ubuntu2, 0, 2.1.5-2ubuntu1 |
| Ubuntu:Pro:16.04:LTS | libjpeg-turbo | 1.4.2-0ubuntu2, 0, 1.4.2-0ubuntu1 |
| Ubuntu:20.04:LTS | libjpeg9 | 0, 1:9d-1, 1:9c-2 |
| Ubuntu:Pro:14.04:LTS | libjpeg-turbo | 1.3.0-0ubuntu1, 0, * |
| Ubuntu:Pro:16.04:LTS | libjpeg9 | 1:9b-1ubuntu1, *, 1:9b-1ubuntu1+esm1 |
| Ubuntu:20.04:LTS | libjpeg-turbo | 2.0.3-0ubuntu1.20.04.3, 0, 2.0.3-0ubuntu1 |
| Ubuntu:18.04:LTS | libjpeg-turbo | 1.5.2-0ubuntu5.18.04.1, 1.5.2-0ubuntu5.18.04.3, 1.5.2-0ubuntu5.18.04.4 |
| Ubuntu:22.04:LTS | libjpeg6b | 0, 1:6b2-3 |
| Ubuntu:25.10 | libjpeg6b | 0, 1:6b2-4 |
| Ubuntu:25.10 | libjpeg-turbo | 2.1.5-4ubuntu2, 2.1.5-3ubuntu2, 0 |
| Ubuntu:Pro:16.04:LTS | libjpeg6b | 1:6b2-2, *, 0 |
Exploit Intelligence
Timeline
- Apr 21, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-10126 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-10126 third-party-advisory
- Multiples vulnérabilités dans VMware Tanzu advisory