← Back

Exiv2

exiv2

124 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Exiv2
exiv2

CVEs (124)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianExiv2+1 more
6Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+3 more
Nov 21, 2024
Nov 8, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
4Canonical
DebianExiv2+1 more
6Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+3 more
Nov 21, 2024
Nov 8, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD im...Show more
In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file.Show less
1Exiv2
1Exiv2
Nov 21, 2024
Nov 3, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.
4Canonical
DebianExiv2+1 more
6Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+3 more
Nov 21, 2024
Sep 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
1Exiv2
1Exiv2
Nov 21, 2024
Sep 20, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
1Exiv2
1Exiv2
Nov 21, 2024
Sep 19, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
1Exiv2
1Exiv2
Nov 21, 2024
Sep 19, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
3Canonical
DebianExiv2
3Debian Linux
Exiv2Ubuntu Linux
Nov 21, 2024
Sep 2, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.
1Exiv2
1Exiv2
Nov 21, 2024
Jul 17, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not used, possibly leading to a buffer overflow.
1Exiv2
1Exiv2
Nov 21, 2024
Jul 13, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.
3Canonical
DebianExiv2
3Debian Linux
Exiv2Ubuntu Linux
Nov 21, 2024
Jun 13, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.
3Canonical
DebianExiv2
3Debian Linux
Exiv2Ubuntu Linux
Nov 21, 2024
Jun 13, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp.
3Canonical
DebianExiv2
3Debian Linux
Exiv2Ubuntu Linux
Nov 21, 2024
May 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
1Exiv2
1Exiv2
Nov 21, 2024
May 14, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.
3Canonical
DebianExiv2
3Debian Linux
Exiv2Ubuntu Linux
Nov 21, 2024
May 12, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read.
4Canonical
DebianExiv2+1 more
6Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+3 more
Nov 21, 2024
May 12, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
3Canonical
DebianExiv2
3Debian Linux
Exiv2Ubuntu Linux
Nov 21, 2024
May 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.
1Exiv2
1Exiv2
Nov 21, 2024
May 7, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Exiv2::Image::byteSwap2 in image.cpp in Exiv2 0.26 has a heap-based buffer over-read.
1Exiv2
1Exiv2
Nov 21, 2024
May 7, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
1Exiv2
1Exiv2
Jun 17, 2026
Apr 4, 2018
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "== 0x1c" case.