Vulnerabilities
Vulnerable Software
Libexif Project:  Security Vulnerabilities
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.
CVSS Score
7.5
EPSS Score
0.054
Published
2012-07-13
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.
CVSS Score
6.8
EPSS Score
0.038
Published
2009-11-20
libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c.
CVSS Score
4.3
EPSS Score
0.044
Published
2007-12-20


Contact Us

Shodan ® - All rights reserved