Vulnerabilities
Vulnerable Software
Exiv2:  >> Exiv2  >> 0.26  Security Vulnerabilities
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-06-30
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
CVSS Score
6.5
EPSS Score
0.002
Published
2019-06-30
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
CVSS Score
6.5
EPSS Score
0.005
Published
2019-06-30
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset.
CVSS Score
6.5
EPSS Score
0.005
Published
2019-06-30
In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-based buffer over-read) via a crafted PNG file.
CVSS Score
6.5
EPSS Score
0.004
Published
2018-11-26
In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file.
CVSS Score
6.5
EPSS Score
0.004
Published
2018-11-08
In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
CVSS Score
6.5
EPSS Score
0.005
Published
2018-11-08
CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
CVSS Score
6.5
EPSS Score
0.003
Published
2018-09-28
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
CVSS Score
6.5
EPSS Score
0.005
Published
2018-09-20
Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
CVSS Score
6.5
EPSS Score
0.005
Published
2018-09-19


Contact Us

Shodan ® - All rights reserved