← Back

Jhead

jhead

Vendor: Jhead Project • 18 CVEs

CVEs (18)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jhead Project
1Jhead
Jun 19, 2025
May 30, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.
1Jhead Project
1Jhead
Jan 3, 2025
Jun 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the st...Show more
Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer overflow problem when multiple `&i` or `&o` are given.Show less
2Debian
Jhead Project
2Debian Linux
Jhead
May 2, 2025
Nov 4, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
3Debian
FedoraprojectJhead Project
3Debian Linux
FedoraJhead
May 13, 2025
Oct 17, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
1Jhead Project
1Jhead
Nov 21, 2024
Mar 23, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
1Jhead Project
1Jhead
Nov 21, 2024
Mar 23, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.
1Jhead Project
1Jhead
Nov 21, 2024
Mar 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.
1Jhead Project
1Jhead
Nov 21, 2024
Mar 23, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.
1Jhead Project
1Jhead
May 5, 2025
Feb 2, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images from digital cameras. In affected versions there is a heap-buffer-overflow on jhead-3.04/jpgfile.c:285...Show more
JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images from digital cameras. In affected versions there is a heap-buffer-overflow on jhead-3.04/jpgfile.c:285 ReadJpegSections. Crafted jpeg images can be provided to the user resulting in a program crash or potentially incorrect exif information retrieval. Users are advised to upgrade. There is no known workaround for this issue.Show less
1Jhead Project
1Jhead
Nov 21, 2024
Apr 22, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.
1Jhead Project
1Jhead
Jun 17, 2026
Jan 9, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
1Jhead Project
1Jhead
Jun 17, 2026
Jan 9, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
1Jhead Project
1Jhead
Jun 17, 2026
Nov 17, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.
3Debian
FedoraprojectJhead Project
3Debian Linux
FedoraJhead
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file.
3Debian
FedoraprojectJhead Project
3Debian Linux
FedoraJhead
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.
1Jhead Project
1Jhead
Nov 21, 2024
Sep 16, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow...Show more
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data length. This is analogous to the CVE-2016-3822 integer overflow in exif.c. This gpsinfo.c vulnerability is unrelated to the CVE-2018-16554 gpsinfo.c vulnerability.Show less
1Jhead Project
1Jhead
Nov 21, 2024
Sep 16, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between floa...Show more
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling.Show less
1Jhead Project
1Jhead
Jun 17, 2026
Feb 4, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-se...Show more
An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact.Show less