Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Unknown
CVE-2020-18831
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file.
0
Attacker Value
Unknown
CVE-2020-18771
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
0
Attacker Value
Unknown
CVE-2020-18773
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
0
Attacker Value
Unknown
CVE-2020-18774
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
0
Attacker Value
Unknown
CVE-2020-18899
Disclosure Date: August 19, 2021 (last updated February 23, 2025)
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.
0
Attacker Value
Unknown
CVE-2020-18898
Disclosure Date: August 19, 2021 (last updated February 23, 2025)
A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
0
Attacker Value
Unknown
CVE-2021-31292
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
0
Attacker Value
Unknown
CVE-2020-19716
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
0
Attacker Value
Unknown
CVE-2021-3482
Disclosure Date: April 08, 2021 (last updated February 22, 2025)
A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.
0
Attacker Value
Unknown
CVE-2019-20421
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
0