Show filters
55 Total Results
Displaying 11-20 of 55
Sort by:
Attacker Value
Unknown
CVE-2018-12264
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp.
0
Attacker Value
Unknown
CVE-2018-11531
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
0
Attacker Value
Unknown
CVE-2018-11037
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.
0
Attacker Value
Unknown
CVE-2018-10999
Disclosure Date: May 12, 2018 (last updated November 26, 2024)
An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read.
0
Attacker Value
Unknown
CVE-2018-10998
Disclosure Date: May 12, 2018 (last updated November 26, 2024)
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
0
Attacker Value
Unknown
CVE-2018-10958
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.
0
Attacker Value
Unknown
CVE-2018-10780
Disclosure Date: May 07, 2018 (last updated November 26, 2024)
Exiv2::Image::byteSwap2 in image.cpp in Exiv2 0.26 has a heap-based buffer over-read.
0
Attacker Value
Unknown
CVE-2018-9145
Disclosure Date: March 30, 2018 (last updated November 26, 2024)
In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.
0
Attacker Value
Unknown
CVE-2018-8977
Disclosure Date: March 25, 2018 (last updated November 26, 2024)
In Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp allows remote attackers to cause a denial of service (invalid memory access) via a crafted file.
0
Attacker Value
Unknown
CVE-2018-8976
Disclosure Date: March 25, 2018 (last updated November 26, 2024)
In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
0