Integer overflow in the jpcpinextcprl function in jpc_t2cod.c in JasPer before 1.900.20 allows remote attackers to have unspecified impact via a crafted file, which triggers use of an uninitialized value.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10251.json"