VYPR

Exif

by Curtis Galloway

CVEs (3)

  • CVE-2021-27815Apr 14, 2021
    risk 0.00cvss epss 0.01

    NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.

  • CVE-2012-2845Jul 13, 2012
    risk 0.00cvss epss 0.04

    Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.

  • CVE-2009-1501May 1, 2009
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.