cbcvebase.

Debian Exiv2 vulnerabilities

73 known vulnerabilities affecting debian/exiv2.

Total CVEs
73
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM33LOW33

Vulnerabilities

Page 4 of 4
CVE-2021-37620P4MEDIUMCVSS 4.7fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37620 [MEDIUM] CVE-2021-37620: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial
debian
CVE-2021-37615P4MEDIUMCVSS 4.7fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37615 [MEDIUM] CVE-2021-37615: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. The null pointer dereference is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to ca
debian
CVE-2025-55304P4LOWCVSS 1.8fixed in exiv2 0.28.7+dfsg-2 (forky)2025
CVE-2025-55304 [LOW] CVE-2025-55304: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. The denial-of-service is triggered when Exiv2 is used to read the meta
debian
CVE-2025-54080P4LOWCVSS 1.8fixed in exiv2 0.28.7+dfsg-2 (forky)2025
CVE-2025-54080 [LOW] CVE-2025-54080: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions 0.28.5 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of
debian
CVE-2021-34334P4MEDIUMCVSS 5.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-34334 [MEDIUM] CVE-2021-34334: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted ima
debian
CVE-2024-25112P4MEDIUMCVSS 5.5fixed in exiv2 0.28.3+dfsg-2 (forky)2024
CVE-2024-25112 [MEDIUM] CVE-2024-25112: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was found in Exiv2 version v0.28.1: an unbounded recursion can cause Exiv2 to crash by exhausting the stack. The vulnerable function, `QuickTimeVideo::multipleEntriesDecoder`, was new in v0.28.0, so Exiv2 versions before v0.2
debian
CVE-2017-18005P4LOWCVSS 5.5fixed in exiv2 0.27.2-6 (bookworm)2017
CVE-2017-18005 [MEDIUM] CVE-2017-18005: exiv2 - Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong functi... Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0.27.2-6) trixie: resolved (fixed in 0.27.2-6)
debian
CVE-2017-14864P4LOWCVSS 5.5fixed in exiv2 0.27.2-6 (bookworm)2017
CVE-2017-14864 [MEDIUM] CVE-2017-14864: exiv2 - An Invalid memory address dereference was discovered in Exiv2::getULong in types... An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0.27.2-6) trix
debian
CVE-2017-14862P4LOWCVSS 5.5fixed in exiv2 0.27.2-6 (bookworm)2017
CVE-2017-14862 [MEDIUM] CVE-2017-14862: exiv2 - An Invalid memory address dereference was discovered in Exiv2::DataValue::read i... An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0.27.2-
debian
CVE-2017-14859P4LOWCVSS 5.5fixed in exiv2 0.27.2-6 (bookworm)2017
CVE-2017-14859 [MEDIUM] CVE-2017-14859: exiv2 - An Invalid memory address dereference was discovered in Exiv2::StringValueBase::... An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0
debian
CVE-2021-29623P4LOWCVSS 3.6fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-29623 [LOW] CVE-2021-29623: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The read of uninitialized memory is triggere
debian
CVE-2021-29473P4LOWCVSS 2.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-29473 [LOW] CVE-2021-29473: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is use
debian
CVE-2008-2696P4LOWCVSS 4.3fixed in exiv2 0.17-1 (bookworm)2008
CVE-2008-2696 [MEDIUM] CVE-2008-2696: exiv2 - Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (d... Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function. Scope: local bookworm: resolved (fixed in 0.17-1) bullseye: resolved (fixed in 0.17-1) forky: resolved (fixed in
debian
Debian Exiv2 vulnerabilities | cvebase