← Back

Jhead

jhead

Vendor: Sentex • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sentex
1Jhead
Apr 23, 2026
Oct 21, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.
1Sentex
1Jhead
Apr 23, 2026
Oct 21, 2008
N/A· v4
N/A· v3
3.6 LOW· v2
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a...Show more
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.Show less
1Sentex
1Jhead
Apr 23, 2026
Oct 21, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
1Sentex
1Jhead
Apr 23, 2026
Oct 15, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of...Show more
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."Show less