Vulnerability index

Browse CVEs

64 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Exiv2 HIGH 7.5
CVE-2026-27596

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, …

Fix: 0.28.8+
Fix from $1,950 2026-03-02
Exiv2 MEDIUM 5.3
CVE-2026-27631

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, …

Fix: after 0.28.8
Fix from $1,600 2026-03-02
Exiv2 HIGH 8.1
CVE-2026-25884

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, …

Fix: 0.28.8+
Fix from $1,950 2026-03-02
Exiv2 MEDIUM 5.5
CVE-2025-54080

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was…

Fix: 0.28.6+
Fix from $1,600 2025-08-29
Exiv2 MEDIUM 5.5
CVE-2025-55304

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was f…

Fix: 0.28.6+
Fix from $1,600 2025-08-29
Exiv2 CRITICAL 9.8
CVE-2025-26623

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A heap buffer overflow wa…

Fix: 0.28.5+
Fix from $2,300 2025-02-18
Exiv2 MEDIUM 6.5
CVE-2024-39695

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was …

Fix: 0.28.3+
Fix from $1,600 2024-07-08
Exiv2 MEDIUM 5.0
CVE-2024-24826

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was …

Patch available
Fix from $1,600 2024-02-12
Exiv2 MEDIUM 5.0
CVE-2024-25112

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was fo…

Patch available
Fix from $1,600 2024-02-12
Exiv2 HIGH 8.8
CVE-2023-44398

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write wa…

Patch available
Fix from $1,950 2023-11-06
Exiv2 HIGH 7.8
CVE-2020-18831

Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and othe…

Patch available
Fix from $1,950 2023-08-22
Exiv2 MEDIUM 6.5
CVE-2020-18773

An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif …

No fix yet
Fix from $1,600 2021-08-23
Exiv2 MEDIUM 6.5
CVE-2020-18774

A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafte…

No fix yet
Fix from $1,600 2021-08-23
Exiv2 MEDIUM 6.5
CVE-2020-18898

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted fil…

No fix yet
Fix from $1,600 2021-08-19
Exiv2 MEDIUM 6.5
CVE-2020-18899

An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS…

No fix yet
Fix from $1,600 2021-08-19
Exiv2 MEDIUM 6.5
CVE-2019-14982

In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buf…

Fix: 0.27.2+
Fix from $1,600 2019-08-12
Exiv2 HIGH 7.8
CVE-2019-14368

Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.

No fix yet
Fix from $1,950 2019-07-28
Exiv2 HIGH 8.8
CVE-2019-9143

An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered b…

No fix yet
Fix from $1,950 2019-02-25
Exiv2 HIGH 8.8
CVE-2019-9144

An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cpp. This can be triggered by a…

No fix yet
Fix from $1,950 2019-02-25
Exiv2 MEDIUM 6.5
CVE-2018-20096

There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote …

Patch available
Fix from $1,600 2018-12-12
Exiv2 MEDIUM 6.5
CVE-2018-20098

There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote d…

Patch available
Fix from $1,600 2018-12-12
Exiv2 MEDIUM 6.5
CVE-2018-20099

There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of serv…

Patch available
Fix from $1,600 2018-12-12
Exiv2 MEDIUM 6.5
CVE-2018-19607

Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application c…

Patch available
Fix from $1,600 2018-11-27
Exiv2 MEDIUM 6.5
CVE-2018-18915

There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denia…

Patch available
Fix from $1,600 2018-11-03
Exiv2 MEDIUM 6.5
CVE-2018-17282

An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

No fix yet
Fix from $1,600 2018-09-20
Exiv2 MEDIUM 6.5
CVE-2018-17229

Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.

No fix yet
Fix from $1,600 2018-09-19
Exiv2 MEDIUM 6.5
CVE-2018-17230

Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.

No fix yet
Fix from $1,600 2018-09-19
Exiv2 HIGH 8.1
CVE-2018-14338

samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not…

Patch available
Fix from $1,950 2018-07-17
Exiv2 HIGH 8.8
CVE-2018-14046

Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.

No fix yet
Fix from $1,950 2018-07-13
Exiv2 MEDIUM 6.5
CVE-2018-11037

In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.

No fix yet
Fix from $1,600 2018-05-14