VYPR

jhead

by Jhead

CVEs (11)

  • CVE-2025-44906HigMay 30, 2025
    risk 0.51cvss 7.8epss 0.00

    jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.

  • CVE-2018-17088HigSep 16, 2018
    risk 0.51cvss 7.8epss 0.02

    The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data…

  • CVE-2018-16554HigSep 16, 2018
    risk 0.51cvss 7.8epss 0.02

    The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT…

  • CVE-2016-3822HigAug 5, 2016
    risk 0.51cvss 7.8epss 0.01

    exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data,…

  • CVE-2020-6625HigJan 9, 2020
    risk 0.46cvss 7.1epss 0.01

    jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.

  • CVE-2020-6624HigJan 9, 2020
    risk 0.46cvss 7.1epss 0.01

    jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.

  • CVE-2019-19035MedNov 17, 2019
    risk 0.36cvss 5.5epss 0.01

    jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.

  • CVE-2019-1010302MedJul 15, 2019
    risk 0.36cvss 5.5epss 0.01

    jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file.

  • CVE-2019-1010301MedJul 15, 2019
    risk 0.36cvss 5.5epss 0.01

    jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.

  • CVE-2018-6612MedFeb 4, 2018
    risk 0.36cvss 5.5epss 0.01

    An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact.

  • CVE-2008-4575Oct 15, 2008
    risk 0.00cvss epss 0.02

    Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."