Vulnerabilities (CVE)

Filtered by vendor Exiv2 Subscribe
Total 124 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1000126 1 Exiv2 1 Exiv2 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
exiv2 0.26 contains a Stack out of bounds read in webp parser
CVE-2014-9449 2 Exiv2, Fedoraproject 2 Exiv2, Fedora 2026-06-17 5.0 MEDIUM N/A
Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows remote attackers to cause a denial of service (crash) via a long IKEY INFO tag value in an AVI file.
CVE-2008-2696 1 Exiv2 1 Exiv2 2026-06-16 4.3 MEDIUM N/A
Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.
CVE-2007-6353 3 Canonical, Debian, Exiv2 3 Ubuntu Linux, Debian Linux, Exiv2 2026-06-16 7.5 HIGH N/A
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.