VYPR
Vendor

Jhead

Products
1
CVEs
19
Across products
19
Status
Private

Products

1

Recent CVEs

19
  • CVE-2025-44906HigMay 30, 2025
    risk 0.51cvss 7.8epss 0.00

    jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.

  • CVE-2021-34055HigNov 4, 2022
    risk 0.51cvss 7.8epss 0.00

    jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.

  • CVE-2021-28278HigMar 23, 2022
    risk 0.51cvss 7.8epss 0.01

    A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.

  • CVE-2021-28277HigMar 23, 2022
    risk 0.51cvss 7.8epss 0.01

    A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.

  • CVE-2021-3496HigApr 22, 2021
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.

  • CVE-2018-17088HigSep 16, 2018
    risk 0.51cvss 7.8epss 0.02

    The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data…

  • CVE-2018-16554HigSep 16, 2018
    risk 0.51cvss 7.8epss 0.02

    The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT…

  • CVE-2016-3822HigAug 5, 2016
    risk 0.51cvss 7.8epss 0.01

    exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data,…

  • CVE-2021-28276HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.

  • CVE-2020-6625HigJan 9, 2020
    risk 0.46cvss 7.1epss 0.01

    jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.

  • CVE-2020-6624HigJan 9, 2020
    risk 0.46cvss 7.1epss 0.01

    jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.

  • CVE-2021-28275MedMar 23, 2022
    risk 0.36cvss 5.5epss 0.01

    A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.

  • CVE-2019-19035MedNov 17, 2019
    risk 0.36cvss 5.5epss 0.01

    jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.

  • CVE-2019-1010302MedJul 15, 2019
    risk 0.36cvss 5.5epss 0.01

    jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file.

  • CVE-2019-1010301MedJul 15, 2019
    risk 0.36cvss 5.5epss 0.01

    jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.

  • CVE-2018-6612MedFeb 4, 2018
    risk 0.36cvss 5.5epss 0.01

    An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact.

  • CVE-2022-41751HigOct 17, 2022
    risk 0.00cvss 7.8epss 0.00

    Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.

  • CVE-2020-26208MedFeb 2, 2022
    risk 0.00cvss 5.3epss 0.01

    JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images from digital cameras. In affected versions there is a heap-buffer-overflow on jhead-3.04/jpgfile.c:285 ReadJpegSections. Crafted jpeg images can be provided to…

  • CVE-2008-4575Oct 15, 2008
    risk 0.00cvss —epss 0.02

    Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."