Skip to content
Noroxi

libexif project records

23 published records for vendor libexif project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
4
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

23 records
  • CVE-2017-7544
    37Monitor

    libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c c

    CriticalCVSS 9.1No exploitEPSS 3%

    libexif project · libexifSep 21, 2017

  • An issue was discovered in libexif before 0.6.22.

    CriticalCVSS 9.1No exploitEPSS 3%

    libexif project · libexifMay 21, 2020

  • An issue was discovered in libexif before 0.6.22.

    HighCVSS 8.2No exploitEPSS 2%

    libexif project · libexifMay 21, 2020

  • CVE-2016-6328
    33Monitor

    A vulnerability was found in libexif.

    HighCVSS 8.1Proof of conceptEPSS 2%

    libexif project · libexifOct 31, 2018

  • CVE-2012-2814
    32Monitor

    Buffer overflow in the exif_entry_format_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 allows remote a

    HighCVSS 7.5No exploitEPSS 8%

    libexif project · libexifJul 13, 2012

  • CVE-2012-2841
    32Monitor

    Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remo

    HighCVSS 7.5No exploitEPSS 6%

    libexif project · libexifJul 13, 2012

  • CVE-2012-2840
    32Monitor

    Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allo

    HighCVSS 7.5No exploitEPSS 5%

    libexif project · libexifJul 13, 2012

  • CVE-2020-0198
    31Monitor

    In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow.

    HighCVSS 7.5Proof of conceptEPSS 4%

    google · androidJun 11, 2020

  • An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust avai

    HighCVSS 7.5No exploitEPSS 4%

    libexif project · libexifFeb 20, 2019

  • CVE-2020-0181
    31Monitor

    In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow.

    HighCVSS 7.5Proof of conceptEPSS 3%

    google · androidJun 11, 2020

  • An issue was discovered in libexif before 0.6.22.

    HighCVSS 7.5No exploitEPSS 2%

    libexif project · libexifMay 21, 2020

  • libexif through 0.6.25 has a flaw in decoding MakerNotes.

    HighCVSS 7.8No exploitEPSS 0%

    libexif project · libexifMar 16, 2026

  • CVE-2009-3895
    29Monitor

    Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remot

    MediumCVSS 6.8No exploitEPSS 5%

    libexif project · libexifNov 20, 2009

  • In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash

    HighCVSS 7.1No exploitEPSS 0%

    libexif project · libexifApr 12, 2026

  • In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes

    HighCVSS 7.1No exploitEPSS 0%

    libexif project · libexifApr 12, 2026

  • CVE-2012-2836
    27Monitor

    The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause

    MediumCVSS 6.4No exploitEPSS 6%

    libexif project · libexifJul 13, 2012

  • CVE-2012-2812
    26Monitor

    The exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cau

    MediumCVSS 6.4No exploitEPSS 4%

    libexif project · libexifJul 13, 2012

  • CVE-2012-2813
    26Monitor

    The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers

    MediumCVSS 6.4No exploitEPSS 4%

    libexif project · libexifJul 13, 2012

  • NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attacker

    MediumCVSS 5.5No exploitEPSS 1%

    libexif project · exifApr 14, 2021

  • exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.

    MediumCVSS 5.5No exploitEPSS 1%

    libexif project · libexifMay 9, 2020

  • CVE-2012-2837
    21Monitor

    The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allo

    MediumCVSS 5.0No exploitEPSS 4%

    libexif project · libexifJul 13, 2012

  • CVE-2020-0093
    20Monitor

    In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check.

    MediumCVSS 5.0No exploitEPSS 0%

    google · androidMay 14, 2020

  • CVE-2007-6351
    18Monitor

    libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with craft

    MediumCVSS 4.3No exploitEPSS 2%

    libexif project · libexifDec 19, 2007