Vulnerabilities > Exiv2 > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-06 CVE-2023-44398 Unspecified vulnerability in Exiv2 0.28.0
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata.
network
low complexity
exiv2
8.8
2023-08-22 CVE-2020-18831 Out-of-bounds Write vulnerability in Exiv2 0.27.1
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file.
local
low complexity
exiv2 CWE-787
7.8
2021-08-23 CVE-2020-18771 Out-of-bounds Read vulnerability in multiple products
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
network
low complexity
exiv2 debian CWE-125
8.1
2021-07-26 CVE-2021-31292 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
network
low complexity
exiv2 debian fedoraproject CWE-190
7.5
2021-04-30 CVE-2021-29464 Out-of-bounds Write vulnerability in multiple products
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files.
local
low complexity
exiv2 fedoraproject CWE-787
7.8
2021-04-19 CVE-2021-29457 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files.
local
low complexity
exiv2 fedoraproject debian
7.8
2020-01-27 CVE-2019-20421 Infinite Loop vulnerability in multiple products
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption.
network
low complexity
exiv2 canonical debian CWE-835
7.5
2019-07-28 CVE-2019-14368 Out-of-bounds Read vulnerability in Exiv2 0.27.99.0
Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.
local
low complexity
exiv2 CWE-125
7.8
2019-02-25 CVE-2019-9144 Uncontrolled Recursion vulnerability in Exiv2 0.27
An issue was discovered in Exiv2 0.27.
network
low complexity
exiv2 CWE-674
8.8
2019-02-25 CVE-2019-9143 Uncontrolled Recursion vulnerability in Exiv2 0.27
An issue was discovered in Exiv2 0.27.
network
low complexity
exiv2 CWE-674
8.8