A double-free issue in JasPer 1.900.1 in the jasperimagestop_load() function can cause a denial of service if a specially crafted JPEG image is loaded (CVE-2015-5203).
A use-after-free which leads to double-free vulnerability was found in Jasper JPEG-2000 library, in src/libjasper/mif/mif_cod.c file (CVE-2015-5221).