CVE-2016-9116 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9116): NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
Affects CLI tool only.
As said multiple times by mitre, a simple crash in a command-line tool where no library are involved is considered an inconvenience instead of a security issue.