← Back

Picasa

picasa

Vendor: Google • 11 CVEs

CVEs (11)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Picasa
May 6, 2026
Nov 17, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, which triggers a heap-based buffer overflow.
1Google
1Picasa
May 6, 2026
Nov 9, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related to "phase one 0x412 tag," which triggers a heap-based buffer overflow.
1Google
1Picasa
Apr 29, 2026
Jan 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 might allow remote attackers to execute arbitrary code via a crafted RAW file, as demonstrated using a KDC file with a certain size.
1Google
1Picasa
Apr 29, 2026
Jan 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to trigger memory corruption via a crafted TIFF tag, as demonstrated using a KDC file with a DSLR-A100 model and certain sequences of tags.
1Google
1Picasa
Apr 29, 2026
Jan 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that triggers a heap-based buffer overflow, as demonstrated using a Canon R...Show more
Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a long TIFF StripByteCounts tag.Show less
1Google
1Picasa
Apr 29, 2026
Jan 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag that triggers a heap-based buffer overflow, as demonstrated using a Can...Show more
Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a large JPEG tag value and a small size.Show less
1Google
1Picasa
Apr 29, 2026
Jul 28, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file.
1Google
1Picasa
Apr 29, 2026
Mar 28, 2011
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.
1Google
1Picasa
Apr 23, 2026
Sep 12, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa:// URI. NOTE: this information is based upon a vague pre-advisory.
1Google
1Picasa
Apr 23, 2026
Sep 11, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple cross-application scripting (XAS) vulnerabilities in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.
1Google
1Picasa
Apr 23, 2026
Sep 11, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.