Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-9145

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.7%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2018-9145
  • Exiv2 » Exiv2 » Version: 0.26
    cpe:2.3:a:exiv2:exiv2:0.26


Contact Us

Shodan ® - All rights reserved