Vulnerabilities > Exiv2 > Exiv2

DATE CVE VULNERABILITY TITLE RISK
2017-08-18 CVE-2017-12955 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Exiv2 0.26
There is a heap-based buffer overflow in basicio.cpp of Exiv2 0.26.
network
exiv2 CWE-119
6.8
2017-07-27 CVE-2017-11683 Reachable Assertion vulnerability in multiple products
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
network
low complexity
exiv2 canonical debian CWE-617
6.5
2017-07-24 CVE-2017-11592 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Exiv2 0.26
There is a Mismatched Memory Management Routines vulnerability in the Exiv2::FileIo::seek function of Exiv2 0.26 that will lead to a remote denial of service attack (heap memory corruption) via crafted input.
network
low complexity
exiv2 CWE-119
5.0
2017-07-24 CVE-2017-11591 There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
network
low complexity
exiv2 canonical debian
7.5
2017-07-23 CVE-2017-11553 Improper Input Validation vulnerability in Exiv2 0.26
There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26.
network
low complexity
exiv2 CWE-20
5.0
2017-07-17 CVE-2017-11340 Improper Input Validation vulnerability in Exiv2 0.26
There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, related to an exit call.
network
exiv2 CWE-20
4.3
2017-07-17 CVE-2017-11339 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Exiv2 0.26
There is a heap-based buffer overflow in the Image::printIFDStructure function of image.cpp in Exiv2 0.26.
network
exiv2 CWE-119
4.3
2017-07-17 CVE-2017-11338 Infinite Loop vulnerability in Exiv2 0.26
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26.
network
exiv2 CWE-835
4.3
2017-07-17 CVE-2017-11337 Use After Free vulnerability in Exiv2 0.26
There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26.
network
exiv2 CWE-416
4.3
2017-07-17 CVE-2017-11336 Out-of-bounds Read vulnerability in Exiv2 0.26
There is a heap-based buffer over-read in the Image::printIFDStructure function in image.cpp in Exiv2 0.26.
network
exiv2 CWE-125
4.3