VYPR

Exif

by Curtis Galloway

CVEs (2)

  • CVE-2012-2845Jul 13, 2012
    risk 0.00cvss epss 0.04

    Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.

  • CVE-2009-1501May 1, 2009
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.