cbcvebase.

Debian Libexif vulnerabilities

26 known vulnerabilities affecting debian/libexif.

Total CVEs
26
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM10LOW3

Vulnerabilities

Page 2 of 2
CVE-2012-2813P4MEDIUMCVSS 6.4fixed in libexif 0.6.20-3 (bookworm)2012
CVE-2012-2813 [MEDIUM] CVE-2012-2813: libexif - The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing ... The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image. Scope: local bookworm: resolved (fixed in 0.6.20-3) bullseye: resolved (fixed in 0
debian
CVE-2012-2837P4MEDIUMCVSS 5.0fixed in libexif 0.6.20-3 (bookworm)2012
CVE-2012-2837 [MEDIUM] CVE-2012-2837: libexif - The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in t... The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags. Scope: local bookworm: resolved (fixed in 0
debian
CVE-2005-0664P4LOWCVSS 2.6fixed in libexif 0.6.9-5 (bookworm)2005
CVE-2005-0664 [LOW] CVE-2005-0664: libexif - Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate t... Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag. Scope: local bookworm: resolved (fixed in 0.6.9-5) bullseye: resolved (fixed in 0.6.9-5) forky: resolve
debian
CVE-2020-0093P4MEDIUMCVSS 5.0fixed in libexif 0.6.21-8 (bookworm)2020
CVE-2020-0093 [MEDIUM] CVE-2020-0093: libexif - In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds r... In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132 Scope: local bookwo
debian
CVE-2020-12767P4MEDIUMCVSS 5.5fixed in libexif 0.6.21-7 (bookworm)2020
CVE-2020-12767 [MEDIUM] CVE-2020-12767: libexif - exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero erro... exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error. Scope: local bookworm: resolved (fixed in 0.6.21-7) bullseye: resolved (fixed in 0.6.21-7) forky: resolved (fixed in 0.6.21-7) sid: resolved (fixed in 0.6.21-7) trixie: resolved (fixed in 0.6.21-7)
debian
CVE-2007-6351P4LOWCVSS 4.3fixed in libexif 0.6.16-2.1 (bookworm)2007
CVE-2007-6351 [MEDIUM] CVE-2007-6351: libexif - libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial ... libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c. Scope: local bookworm: resolved (fixed in 0.6.16-2.1) bullseye: resolved (fixed in 0.6.16-2.1) forky: resolved (fixed in 0.6.16-2.1) sid: resolved
debian
Debian Libexif vulnerabilities | cvebase