libexif project records
23 published records for vendor libexif project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-190 Integer Overflow or Wraparound4
- CWE-125 Out-of-bounds Read3
- CWE-189 Numeric Errors3
- CWE-191 Integer Underflow (Wrap or Wraparound)2
- CWE-908 Use of Uninitialized Resource1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2017-7544No exploit | libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c clibexif project · libexif · CWE-125 | Critical9.1 | — | 3.3% | Sep 21, 2017 |
37Monitor | CVE-2020-13112No exploit | An issue was discovered in libexif before 0.6.22.libexif project · libexif · CWE-125 | Critical9.1 | — | 2.7% | May 21, 2020 |
33Monitor | CVE-2020-13113No exploit | An issue was discovered in libexif before 0.6.22.libexif project · libexif · CWE-908 | High8.2 | — | 1.9% | May 21, 2020 |
33Monitor | CVE-2016-6328Proof of concept | A vulnerability was found in libexif.libexif project · libexif · CWE-190 | High8.1 | — | 1.7% | Oct 31, 2018 |
32Monitor | CVE-2012-2814No exploit | Buffer overflow in the exif_entry_format_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 allows remote alibexif project · libexif · CWE-119 | High7.5 | — | 7.6% | Jul 13, 2012 |
32Monitor | CVE-2012-2841No exploit | Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remolibexif project · libexif · CWE-189 | High7.5 | — | 5.7% | Jul 13, 2012 |
32Monitor | CVE-2012-2840No exploit | Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allolibexif project · libexif · CWE-189 | High7.5 | — | 5.0% | Jul 13, 2012 |
31Monitor | CVE-2020-0198Proof of concept | In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow.google · android · CWE-190 | High7.5 | — | 4.3% | Jun 11, 2020 |
31Monitor | CVE-2018-20030No exploit | An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust availibexif project · libexif · CWE-400 | High7.5 | — | 3.8% | Feb 20, 2019 |
31Monitor | CVE-2020-0181Proof of concept | In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow.google · android · CWE-190 | High7.5 | — | 2.9% | Jun 11, 2020 |
31Monitor | CVE-2020-13114No exploit | An issue was discovered in libexif before 0.6.22.libexif project · libexif · CWE-770 | High7.5 | — | 2.3% | May 21, 2020 |
31Monitor | CVE-2026-32775No exploit | libexif through 0.6.25 has a flaw in decoding MakerNotes.libexif project · libexif · CWE-191 | High7.8 | — | 0.2% | Mar 16, 2026 |
29Monitor | CVE-2009-3895No exploit | Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remotlibexif project · libexif · CWE-119 | Medium6.8 | — | 5.1% | Nov 20, 2009 |
28Monitor | CVE-2026-40386No exploit | In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crashlibexif project · libexif · CWE-191 | High7.1 | — | 0.1% | Apr 12, 2026 |
28Monitor | CVE-2026-40385No exploit | In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes libexif project · libexif · CWE-190 | High7.1 | — | 0.1% | Apr 12, 2026 |
27Monitor | CVE-2012-2836No exploit | The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to causelibexif project · libexif · CWE-119 | Medium6.4 | — | 6.2% | Jul 13, 2012 |
26Monitor | CVE-2012-2812No exploit | The exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to caulibexif project · libexif · CWE-119 | Medium6.4 | — | 3.9% | Jul 13, 2012 |
26Monitor | CVE-2012-2813No exploit | The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers libexif project · libexif · CWE-119 | Medium6.4 | — | 3.8% | Jul 13, 2012 |
22Monitor | CVE-2021-27815No exploit | NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackerlibexif project · exif · CWE-476 | Medium5.5 | — | 1.3% | Apr 14, 2021 |
22Monitor | CVE-2020-12767No exploit | exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.libexif project · libexif · CWE-369 | Medium5.5 | — | 0.5% | May 9, 2020 |
21Monitor | CVE-2012-2837No exploit | The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allolibexif project · libexif · CWE-189 | Medium5.0 | — | 3.9% | Jul 13, 2012 |
20Monitor | CVE-2020-0093No exploit | In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check.google · android · CWE-125 | Medium5.0 | — | 0.3% | May 14, 2020 |
18Monitor | CVE-2007-6351No exploit | libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with craftlibexif project · libexif | Medium4.3 | — | 1.7% | Dec 19, 2007 |
- CVE-2017-754437Monitor
libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c c
CriticalCVSS 9.1No exploitEPSS 3%libexif project · libexifSep 21, 2017
- CVE-2020-1311237Monitor
An issue was discovered in libexif before 0.6.22.
CriticalCVSS 9.1No exploitEPSS 3%libexif project · libexifMay 21, 2020
- CVE-2020-1311333Monitor
An issue was discovered in libexif before 0.6.22.
HighCVSS 8.2No exploitEPSS 2%libexif project · libexifMay 21, 2020
- CVE-2016-632833Monitor
A vulnerability was found in libexif.
HighCVSS 8.1Proof of conceptEPSS 2%libexif project · libexifOct 31, 2018
- CVE-2012-281432Monitor
Buffer overflow in the exif_entry_format_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 allows remote a
HighCVSS 7.5No exploitEPSS 8%libexif project · libexifJul 13, 2012
- CVE-2012-284132Monitor
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remo
HighCVSS 7.5No exploitEPSS 6%libexif project · libexifJul 13, 2012
- CVE-2012-284032Monitor
Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allo
HighCVSS 7.5No exploitEPSS 5%libexif project · libexifJul 13, 2012
- CVE-2020-019831Monitor
In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow.
HighCVSS 7.5Proof of conceptEPSS 4%google · androidJun 11, 2020
- CVE-2018-2003031Monitor
An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust avai
HighCVSS 7.5No exploitEPSS 4%libexif project · libexifFeb 20, 2019
- CVE-2020-018131Monitor
In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow.
HighCVSS 7.5Proof of conceptEPSS 3%google · androidJun 11, 2020
- CVE-2020-1311431Monitor
An issue was discovered in libexif before 0.6.22.
HighCVSS 7.5No exploitEPSS 2%libexif project · libexifMay 21, 2020
- CVE-2026-3277531Monitor
libexif through 0.6.25 has a flaw in decoding MakerNotes.
HighCVSS 7.8No exploitEPSS 0%libexif project · libexifMar 16, 2026
- CVE-2009-389529Monitor
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remot
MediumCVSS 6.8No exploitEPSS 5%libexif project · libexifNov 20, 2009
- CVE-2026-4038628Monitor
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash
HighCVSS 7.1No exploitEPSS 0%libexif project · libexifApr 12, 2026
- CVE-2026-4038528Monitor
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes
HighCVSS 7.1No exploitEPSS 0%libexif project · libexifApr 12, 2026
- CVE-2012-283627Monitor
The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause
MediumCVSS 6.4No exploitEPSS 6%libexif project · libexifJul 13, 2012
- CVE-2012-281226Monitor
The exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cau
MediumCVSS 6.4No exploitEPSS 4%libexif project · libexifJul 13, 2012
- CVE-2012-281326Monitor
The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers
MediumCVSS 6.4No exploitEPSS 4%libexif project · libexifJul 13, 2012
- CVE-2021-2781522Monitor
NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attacker
MediumCVSS 5.5No exploitEPSS 1%libexif project · exifApr 14, 2021
- CVE-2020-1276722Monitor
exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
MediumCVSS 5.5No exploitEPSS 1%libexif project · libexifMay 9, 2020
- CVE-2012-283721Monitor
The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allo
MediumCVSS 5.0No exploitEPSS 4%libexif project · libexifJul 13, 2012
- CVE-2020-009320Monitor
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check.
MediumCVSS 5.0No exploitEPSS 0%google · androidMay 14, 2020
- CVE-2007-635118Monitor
libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with craft
MediumCVSS 4.3No exploitEPSS 2%libexif project · libexifDec 19, 2007