Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Exiv2 MEDIUM 6.5
CVE-2020-18773

An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif …

No fix yet
Fix from $1,600 2021-08-23
Exiv2 MEDIUM 6.5
CVE-2020-18774

A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafte…

No fix yet
Fix from $1,600 2021-08-23
Exiv2 MEDIUM 6.5
CVE-2020-18898

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted fil…

No fix yet
Fix from $1,600 2021-08-19
Exiv2 MEDIUM 6.5
CVE-2020-18899

An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS…

No fix yet
Fix from $1,600 2021-08-19
Exiv2 HIGH 7.8
CVE-2019-14368

Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.

No fix yet
Fix from $1,950 2019-07-28
Exiv2 HIGH 8.8
CVE-2019-9143

An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered b…

No fix yet
Fix from $1,950 2019-02-25
Exiv2 HIGH 8.8
CVE-2019-9144

An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cpp. This can be triggered by a…

No fix yet
Fix from $1,950 2019-02-25
Exiv2 MEDIUM 6.5
CVE-2018-17282

An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

No fix yet
Fix from $1,600 2018-09-20
Exiv2 MEDIUM 6.5
CVE-2018-17229

Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.

No fix yet
Fix from $1,600 2018-09-19
Exiv2 MEDIUM 6.5
CVE-2018-17230

Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.

No fix yet
Fix from $1,600 2018-09-19
Exiv2 HIGH 8.8
CVE-2018-14046

Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.

No fix yet
Fix from $1,950 2018-07-13
Exiv2 MEDIUM 6.5
CVE-2018-11037

In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.

No fix yet
Fix from $1,600 2018-05-14
Exiv2 MEDIUM 6.5
CVE-2018-10780

Exiv2::Image::byteSwap2 in image.cpp in Exiv2 0.26 has a heap-based buffer over-read.

No fix yet
Fix from $1,600 2018-05-07
Exiv2 MEDIUM 6.5
CVE-2018-9145

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may…

No fix yet
Fix from $1,600 2018-03-30
Exiv2 HIGH 8.1
CVE-2017-17723

In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnera…

No fix yet
Fix from $1,950 2018-02-12
Exiv2 MEDIUM 6.5
CVE-2017-17722

In Exiv2 0.26, there is a reachable assertion in the readHeader function in bigtiffimage.cpp, which will lead to a remote denial of service attack vi…

No fix yet
Fix from $1,600 2018-02-12
Exiv2 MEDIUM 6.5
CVE-2017-17724

In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::IptcData::printStructure function in iptc.cpp, related to the "!= 0x1c" case. Rem…

No fix yet
Fix from $1,600 2018-02-12
Exiv2 MEDIUM 6.5
CVE-2017-17725

In Exiv2 0.26, there is an integer overflow leading to a heap-based buffer over-read in the Exiv2::getULong function in types.cpp. Remote attackers c…

No fix yet
Fix from $1,600 2018-02-12
Exiv2 MEDIUM 5.5
CVE-2018-5772

In Exiv2 0.26, there is a segmentation fault caused by uncontrolled recursion in the Exiv2::Image::printIFDStructure function in the image.cpp file. …

No fix yet
Fix from $1,600 2018-01-18
Exiv2 MEDIUM 5.5
CVE-2018-4868

The Exiv2::Jp2Image::readMetadata function in jp2image.cpp in Exiv2 0.26 allows remote attackers to cause a denial of service (excessive memory alloc…

No fix yet
Fix from $1,600 2018-01-03
Exiv2 MEDIUM 5.5
CVE-2017-1000126

exiv2 0.26 contains a Stack out of bounds read in webp parser

Mitigation only
Fix from $1,600 2017-11-17
Exiv2 MEDIUM 5.5
CVE-2017-1000127

Exiv2 0.26 contains a heap buffer overflow in tiff parser

Mitigation only
Fix from $1,600 2017-11-17
Exiv2 MEDIUM 5.5
CVE-2017-1000128

Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser

Mitigation only
Fix from $1,600 2017-11-17
Exiv2 MEDIUM 5.5
CVE-2017-14866

There is a heap-based buffer overflow in the Exiv2::s2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service atta…

No fix yet
Fix from $1,600 2017-09-29
Exiv2 MEDIUM 5.5
CVE-2017-14857

In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a denial of …

No fix yet
Fix from $1,600 2017-09-29
Exiv2 MEDIUM 5.5
CVE-2017-14858

There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service atta…

No fix yet
Fix from $1,600 2017-09-29
Exiv2 MEDIUM 5.5
CVE-2017-14860

There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will lead to a de…

No fix yet
Fix from $1,600 2017-09-29
Exiv2 MEDIUM 5.5
CVE-2017-14861

There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will lead to a r…

No fix yet
Fix from $1,600 2017-09-29
Exiv2 MEDIUM 5.5
CVE-2017-14863

A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerability causes a segmentation faul…

No fix yet
Fix from $1,600 2017-09-29
Exiv2 MEDIUM 5.5
CVE-2017-14865

There is a heap-based buffer overflow in the Exiv2::us2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service att…

Mitigation only
Fix from $1,600 2017-09-29