Exiv2 records
124 published records for vendor exiv2.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 86.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read40
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer16
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')9
- CWE-190 Integer Overflow or Wraparound8
- CWE-476 NULL Pointer Dereference7
- CWE-787 Out-of-bounds Write6
The weakness classes this vendor ships most often: where to look.
CWEAll records
124 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-11531No exploit | Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.exiv2 · exiv2 · CWE-787 | Critical9.8 | — | 3.0% | May 29, 2018 |
36Monitor | CVE-2018-12264No exploit | Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea exiv2 · exiv2 · CWE-125 | High8.8 | — | 2.9% | Jun 13, 2018 |
36Monitor | CVE-2018-12265No exploit | Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basexiv2 · exiv2 · CWE-125 | High8.8 | — | 2.9% | Jun 13, 2018 |
36Monitor | CVE-2019-9144No exploit | An issue was discovered in Exiv2 0.27.exiv2 · exiv2 · CWE-674 | High8.8 | — | 2.8% | Feb 25, 2019 |
36Monitor | CVE-2019-9143No exploit | An issue was discovered in Exiv2 0.27.exiv2 · exiv2 · CWE-674 | High8.8 | — | 2.8% | Feb 25, 2019 |
36Monitor | CVE-2018-14046No exploit | Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.exiv2 · exiv2 · CWE-125 | High8.8 | — | 1.7% | Jul 13, 2018 |
36Monitor | CVE-2017-12955No exploit | There is a heap-based buffer overflow in basicio.cpp of Exiv2 0.26.exiv2 · exiv2 · CWE-119 | High8.8 | — | 1.7% | Aug 18, 2017 |
35Monitor | CVE-2023-44398No exploit | Out-of-bounds write in exiv2exiv2 · exiv2 · CWE-787 | High8.8 | — | 1.0% | Nov 6, 2023 |
33Monitor | CVE-2018-9305No exploit | In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "== 0exiv2 · exiv2 · CWE-125 | High8.1 | — | 1.9% | Apr 4, 2018 |
33Monitor | CVE-2018-9144No exploit | In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp.exiv2 · exiv2 · CWE-125 | High8.1 | — | 1.8% | Mar 30, 2018 |
33Monitor | CVE-2020-18771No exploit | Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an infexiv2 · exiv2 · CWE-125 | High8.1 | — | 1.8% | Aug 23, 2021 |
33Monitor | CVE-2017-17723No exploit | In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp.exiv2 · exiv2 · CWE-125 | High8.1 | — | 1.8% | Feb 12, 2018 |
32Monitor | CVE-2021-29457No exploit | Heap buffer overflow in Exiv2::Jp2Image::doWriteMetadataexiv2 · exiv2 · CWE-122 | High7.8 | — | 2.2% | Apr 19, 2021 |
32Monitor | CVE-2018-14338No exploit | samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where gliexiv2 · exiv2 · CWE-119 | High8.1 | — | 1.4% | Jul 17, 2018 |
31Monitor | CVE-2007-6353No exploit | Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that trigexiv2 · exiv2 · CWE-190 | High7.5 | — | 4.9% | Dec 19, 2007 |
31Monitor | CVE-2019-20421No exploit | In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumptioexiv2 · exiv2 · CWE-835 | High7.5 | — | 4.3% | Jan 27, 2020 |
31Monitor | CVE-2017-11591No exploit | There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via cexiv2 · exiv2 | High7.5 | — | 3.1% | Jul 23, 2017 |
31Monitor | CVE-2017-9953No exploit | There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26.exiv2 · exiv2 · CWE-416 | High7.5 | — | 2.8% | Jun 26, 2017 |
31Monitor | CVE-2021-31292No exploit | An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of sexiv2 · exiv2 · CWE-190 | High7.5 | — | 2.6% | Jul 26, 2021 |
31Monitor | CVE-2017-11592No exploit | There is a Mismatched Memory Management Routines vulnerability in the Exiv2::FileIo::seek function of Exiv2 0.26 that will lead to a remote exiv2 · exiv2 · CWE-119 | High7.5 | — | 1.7% | Jul 23, 2017 |
31Monitor | CVE-2017-11553No exploit | There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26.exiv2 · exiv2 · CWE-20 | High7.5 | — | 1.7% | Jul 22, 2017 |
31Monitor | CVE-2021-29464No exploit | Heap buffer overflow in Exiv2::Jp2Image::encodeJp2Headerexiv2 · exiv2 · CWE-122 | High7.8 | — | 1.5% | Apr 30, 2021 |
31Monitor | CVE-2019-14368No exploit | Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.exiv2 · exiv2 · CWE-125 | High7.8 | — | 1.1% | Jul 28, 2019 |
31Monitor | CVE-2020-18831No exploit | Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of serviceexiv2 · exiv2 · CWE-787 | High7.8 | — | 0.8% | Aug 22, 2023 |
27Monitor | CVE-2018-20096No exploit | There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3.exiv2 · exiv2 · CWE-125 | Medium6.5 | — | 2.8% | Dec 12, 2018 |
- CVE-2018-1153140Plan
Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
CriticalCVSS 9.8No exploitEPSS 3%exiv2 · exiv2May 29, 2018
- CVE-2018-1226436Monitor
Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea
HighCVSS 8.8No exploitEPSS 3%exiv2 · exiv2Jun 13, 2018
- CVE-2018-1226536Monitor
Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in bas
HighCVSS 8.8No exploitEPSS 3%exiv2 · exiv2Jun 13, 2018
- CVE-2019-914436Monitor
An issue was discovered in Exiv2 0.27.
HighCVSS 8.8No exploitEPSS 3%exiv2 · exiv2Feb 25, 2019
- CVE-2019-914336Monitor
An issue was discovered in Exiv2 0.27.
HighCVSS 8.8No exploitEPSS 3%exiv2 · exiv2Feb 25, 2019
- CVE-2018-1404636Monitor
Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.
HighCVSS 8.8No exploitEPSS 2%exiv2 · exiv2Jul 13, 2018
- CVE-2017-1295536Monitor
There is a heap-based buffer overflow in basicio.cpp of Exiv2 0.26.
HighCVSS 8.8No exploitEPSS 2%exiv2 · exiv2Aug 18, 2017
- CVE-2023-4439835Monitor
Out-of-bounds write in exiv2
HighCVSS 8.8No exploitEPSS 1%exiv2 · exiv2Nov 6, 2023
- CVE-2018-930533Monitor
In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "== 0
HighCVSS 8.1No exploitEPSS 2%exiv2 · exiv2Apr 4, 2018
- CVE-2018-914433Monitor
In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp.
HighCVSS 8.1No exploitEPSS 2%exiv2 · exiv2Mar 30, 2018
- CVE-2020-1877133Monitor
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an inf
HighCVSS 8.1No exploitEPSS 2%exiv2 · exiv2Aug 23, 2021
- CVE-2017-1772333Monitor
In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp.
HighCVSS 8.1No exploitEPSS 2%exiv2 · exiv2Feb 12, 2018
- CVE-2021-2945732Monitor
Heap buffer overflow in Exiv2::Jp2Image::doWriteMetadata
HighCVSS 7.8No exploitEPSS 2%exiv2 · exiv2Apr 19, 2021
- CVE-2018-1433832Monitor
samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where gli
HighCVSS 8.1No exploitEPSS 1%exiv2 · exiv2Jul 17, 2018
- CVE-2007-635331Monitor
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that trig
HighCVSS 7.5No exploitEPSS 5%exiv2 · exiv2Dec 19, 2007
- CVE-2019-2042131Monitor
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumptio
HighCVSS 7.5No exploitEPSS 4%exiv2 · exiv2Jan 27, 2020
- CVE-2017-1159131Monitor
There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via c
HighCVSS 7.5No exploitEPSS 3%exiv2 · exiv2Jul 23, 2017
- CVE-2017-995331Monitor
There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26.
HighCVSS 7.5No exploitEPSS 3%exiv2 · exiv2Jun 26, 2017
- CVE-2021-3129231Monitor
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of s
HighCVSS 7.5No exploitEPSS 3%exiv2 · exiv2Jul 26, 2021
- CVE-2017-1159231Monitor
There is a Mismatched Memory Management Routines vulnerability in the Exiv2::FileIo::seek function of Exiv2 0.26 that will lead to a remote
HighCVSS 7.5No exploitEPSS 2%exiv2 · exiv2Jul 23, 2017
- CVE-2017-1155331Monitor
There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26.
HighCVSS 7.5No exploitEPSS 2%exiv2 · exiv2Jul 22, 2017
- CVE-2021-2946431Monitor
Heap buffer overflow in Exiv2::Jp2Image::encodeJp2Header
HighCVSS 7.8No exploitEPSS 1%exiv2 · exiv2Apr 30, 2021
- CVE-2019-1436831Monitor
Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.
HighCVSS 7.8No exploitEPSS 1%exiv2 · exiv2Jul 28, 2019
- CVE-2020-1883131Monitor
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service
HighCVSS 7.8No exploitEPSS 1%exiv2 · exiv2Aug 22, 2023
- CVE-2018-2009627Monitor
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3.
MediumCVSS 6.5No exploitEPSS 3%exiv2 · exiv2Dec 12, 2018