Записи exiftool project
4 опубликованных записей вендора exiftool project.
Профиль для исследователя
- Попали в KEV
- 1 · 25 %
- С эксплойтом
- 1 · 25 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- 208 дн.
Повторяющиеся классы
- CWE-427 Uncontrolled Search Path Element1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
91Срочно | CVE-2021-22204Готовый эксплойт | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing texiftool project · exiftool · CWE-94 | Высокая7,8 | KEV | 100,0 % | 23 апр. 2021 г. |
33Наблюдать | CVE-2022-23935Proof of concept | lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.exiftool project · exiftool · CWE-78 | Высокая7,8 | — | 7,6 % | 25 янв. 2022 г. |
31Наблюдать | CVE-2018-20211Эксплойта нет | ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with a victim's username,exiftool project · exiftool · CWE-427 | Высокая7,8 | — | 1,4 % | 2 янв. 2019 г. |
9Наблюдать | CVE-2026-3102Proof of concept | exiftool PNG File MacOS.pm SetMacOSTags os command injectionexiftool project · exiftool · CWE-77 | Низкая2,1 | — | 2,8 % | 24 февр. 2026 г. |
- CVE-2021-2220491Срочно
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing t
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 100 %exiftool project · exiftool23 апр. 2021 г.
- CVE-2022-2393533Наблюдать
lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.
ВысокаяCVSS 7,8Proof of conceptEPSS 8 %exiftool project · exiftool25 янв. 2022 г.
- CVE-2018-2021131Наблюдать
ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with a victim's username,
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %exiftool project · exiftool2 янв. 2019 г.
- CVE-2026-31029Наблюдать
exiftool PNG File MacOS.pm SetMacOSTags os command injection
НизкаяCVSS 2,1Proof of conceptEPSS 3 %exiftool project · exiftool24 февр. 2026 г.