VYPR

Exiv2

by Exiv2

pypi: exiv2

Source repositories

CVEs (125)

  • CVE-2020-18774MedAug 23, 2021
    risk 0.42cvss 6.5epss 0.01

    A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.

  • CVE-2020-18773MedAug 23, 2021
    risk 0.42cvss 6.5epss 0.01

    An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.

  • CVE-2020-18899MedAug 19, 2021
    risk 0.42cvss 6.5epss 0.02

    An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.

  • CVE-2020-18898MedAug 19, 2021
    risk 0.42cvss 6.5epss 0.01

    A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

  • CVE-2020-19716MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.01

    A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).

  • CVE-2021-3482MedApr 8, 2021
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.

  • CVE-2019-20421HigJan 27, 2020
    risk 0.42cvss 7.5epss 0.04

    In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

  • CVE-2019-17402MedOct 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.

  • CVE-2019-14370MedJul 28, 2019
    risk 0.42cvss 6.5epss 0.01

    In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.

  • CVE-2019-14369MedJul 28, 2019
    risk 0.42cvss 6.5epss 0.01

    Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file.

  • CVE-2018-20099MedDec 12, 2018
    risk 0.42cvss 6.5epss 0.02

    There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-20098MedDec 12, 2018
    risk 0.42cvss 6.5epss 0.03

    There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-20097MedDec 12, 2018
    risk 0.42cvss 6.5epss 0.02

    There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-20096MedDec 12, 2018
    risk 0.42cvss 6.5epss 0.03

    There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-19607MedNov 27, 2018
    risk 0.42cvss 6.5epss 0.03

    Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

  • CVE-2018-18915MedNov 3, 2018
    risk 0.42cvss 6.5epss 0.02

    There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-17581MedSep 28, 2018
    risk 0.42cvss 6.5epss 0.02

    CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.

  • CVE-2018-17282MedSep 20, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

  • CVE-2018-17230MedSep 19, 2018
    risk 0.42cvss 6.5epss 0.02

    Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.

  • CVE-2018-17229MedSep 19, 2018
    risk 0.42cvss 6.5epss 0.02

    Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.

Page 2 of 7