exiftool project kayıtları
exiftool project üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %25
- Silahlaştırılmış
- 1 · %25
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %75
- Yayından KEV’e ortanca
- 208 gün
Tekrar eden sınıflar
- CWE-427 Uncontrolled Search Path Element1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
91Hemen | CVE-2021-22204Silahlaştırılmış | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing texiftool project · exiftool · CWE-94 | Yüksek7,8 | KEV | %100,0 | 23 Nis 2021 |
33İzleyin | CVE-2022-23935Kavram kanıtı | lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.exiftool project · exiftool · CWE-78 | Yüksek7,8 | — | %7,6 | 25 Oca 2022 |
31İzleyin | CVE-2018-20211İstismar yok | ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with a victim's username,exiftool project · exiftool · CWE-427 | Yüksek7,8 | — | %1,4 | 2 Oca 2019 |
9İzleyin | CVE-2026-3102Kavram kanıtı | exiftool PNG File MacOS.pm SetMacOSTags os command injectionexiftool project · exiftool · CWE-77 | Düşük2,1 | — | %2,8 | 24 Şub 2026 |
- CVE-2021-2220491Hemen
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing t
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100exiftool project · exiftool23 Nis 2021
- CVE-2022-2393533İzleyin
lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.
YüksekCVSS 7,8Kavram kanıtıEPSS %8exiftool project · exiftool25 Oca 2022
- CVE-2018-2021131İzleyin
ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with a victim's username,
YüksekCVSS 7,8İstismar yokEPSS %1exiftool project · exiftool2 Oca 2019
- CVE-2026-31029İzleyin
exiftool PNG File MacOS.pm SetMacOSTags os command injection
DüşükCVSS 2,1Kavram kanıtıEPSS %3exiftool project · exiftool24 Şub 2026