Vulnerabilities > Exiv2 > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-17 CVE-2018-14338 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Exiv2 0.26
samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not used, possibly leading to a buffer overflow.
network
high complexity
exiv2 CWE-119
8.1
2018-07-13 CVE-2018-14046 Out-of-bounds Read vulnerability in Exiv2 0.26
Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.
network
low complexity
exiv2 CWE-125
8.8
2018-06-13 CVE-2018-12265 Integer Overflow or Wraparound vulnerability in multiple products
Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.
network
low complexity
exiv2 debian canonical CWE-190
8.8
2018-06-13 CVE-2018-12264 Integer Overflow or Wraparound vulnerability in multiple products
Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp.
network
low complexity
exiv2 debian canonical CWE-190
8.8
2018-04-04 CVE-2018-9305 Out-of-bounds Read vulnerability in Exiv2
In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "== 0x1c" case.
network
low complexity
exiv2 CWE-125
8.1
2018-03-30 CVE-2018-9144 Out-of-bounds Read vulnerability in Exiv2
In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp.
network
low complexity
exiv2 CWE-125
8.1
2018-02-12 CVE-2017-17723 Out-of-bounds Read vulnerability in Exiv2 0.26
In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp.
network
low complexity
exiv2 CWE-125
8.1
2017-08-18 CVE-2017-12955 Out-of-bounds Write vulnerability in Exiv2 0.26
There is a heap-based buffer overflow in basicio.cpp of Exiv2 0.26.
network
low complexity
exiv2 CWE-787
8.8
2017-07-24 CVE-2017-11592 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Exiv2 0.26
There is a Mismatched Memory Management Routines vulnerability in the Exiv2::FileIo::seek function of Exiv2 0.26 that will lead to a remote denial of service attack (heap memory corruption) via crafted input.
network
low complexity
exiv2 CWE-119
7.5
2017-07-24 CVE-2017-11591 There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
network
low complexity
exiv2 canonical debian
7.5