Vulnerabilities > Jhead Project > Jhead > 3.00

DATE CVE VULNERABILITY TITLE RISK
2018-09-16 CVE-2018-17088 Integer Overflow or Wraparound vulnerability in Jhead Project Jhead 3.00
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data length.
6.8
2018-09-16 CVE-2018-16554 Use of Externally-Controlled Format String vulnerability in Jhead Project Jhead 3.00
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling.
6.8