CVE-2024-23077

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
10/04/2024
Last modified:
27/05/2025

Description

JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.java. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jfree:jfreechart:1.5.4:*:*:*:*:*:*:*