Jhead Project Jhead vulnerabilities
24 known vulnerabilities affecting jhead_project/jhead.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH13MEDIUM8LOW1
Vulnerabilities
Page 1 of 2
CVE-2022-28550P3CRITICALCVSS 9.8v3.062023-06-13
CVE-2022-28550 [CRITICAL] CWE-787 CVE-2022-28550: Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead.
Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer overflow problem when multiple `&i` or `&o` are given.
nvdosv
CVE-2008-4641P3CRITICALCVSS 10.0≥ 0, < 2.84-22008-10-21
CVE-2008-4641 [CRITICAL] CVE-2008-4641: The DoCommand function in jhead
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.
osv
CVE-2022-41751P3HIGHCVSS 7.8v3.06.0.12022-10-17
CVE-2022-41751 [HIGH] CWE-78 CVE-2022-41751: Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
nvdosv
CVE-2016-3822P3HIGHCVSS 7.8≥ 0, < 1:3.00-42016-08-05
CVE-2016-3822 [HIGH] CVE-2016-3822: exif
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data, aka internal bug 28868315.
osv
CVE-2021-28277P3HIGHCVSS 7.8v3.04v3.052022-03-23
CVE-2021-28277 [HIGH] CWE-787 CVE-2021-28277: A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overf
A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.
nvdosv
CVE-2018-17088P3HIGHCVSS 7.8v3.002018-09-16
CVE-2018-17088 [HIGH] CVE-2018-17088: The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data length. This is analogous to the CVE-2016-3822 integer overflow in exif.c. This g
nvdosv
CVE-2021-28278P3HIGHCVSS 7.8v3.04v3.052022-03-23
CVE-2021-28278 [HIGH] CWE-787 CVE-2021-28278: A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType f
A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
nvdosv
CVE-2020-28840P3HIGHCVSS 7.8≥ 0, < 1:3.06.0.1-22023-08-11
CVE-2020-28840 [HIGH] CVE-2020-28840: Buffer Overflow vulnerability in jpgfile
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
osv
CVE-2021-3496P4HIGHCVSS 7.8v3.06vjhead 3.06.0.12021-04-22
CVE-2021-3496 [HIGH] CWE-119 CVE-2021-3496: A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processin
A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.
nvdosv
CVE-2021-34055P4HIGHCVSS 7.8v3.062022-11-04
CVE-2021-34055 [HIGH] CWE-120 CVE-2021-34055: jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
nvdosv
CVE-2021-28276P4HIGHCVSS 7.5v3.04v3.052022-03-23
CVE-2021-28276 [HIGH] CVE-2021-28276: A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the Proce
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.
nvdosv
CVE-2025-44906P4HIGHCVSS 7.8v3.082025-05-30
CVE-2025-44906 [HIGH] CWE-416 CVE-2025-44906: jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.
jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.
nvd
CVE-2018-16554P4HIGHCVSS 7.8v3.002018-09-16
CVE-2018-16554 [HIGH] CWE-134 CVE-2018-16554: The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling.
nvdosv
CVE-2020-6625P4HIGHCVSS 7.1≤ 3.042020-01-09
CVE-2020-6625 [HIGH] CWE-125 CVE-2020-6625: jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gp
jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
nvd
CVE-2020-6624P4HIGHCVSS 7.1≤ 3.042020-01-09
CVE-2020-6624 [HIGH] CWE-125 CVE-2020-6624: jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
nvd
CVE-2020-26208P4MEDIUMCVSS 6.1fixed in 3.042022-02-02
CVE-2020-26208 [MEDIUM] CWE-787 CVE-2020-26208: JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedde
JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images from digital cameras. In affected versions there is a heap-buffer-overflow on jhead-3.04/jpgfile.c:285 ReadJpegSections. Crafted jpeg images can be provided to the user resulting in a program crash or potentially incorrect exif inform
nvdosv
CVE-2019-1010301P4MEDIUMCVSS 5.5v3.032019-07-15
CVE-2019-1010301 [MEDIUM] CWE-787 CVE-2019-1010301: jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsi
jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.
nvdosv
CVE-2018-6612P4MEDIUMCVSS 5.5v3.02018-02-04
CVE-2018-6612 [MEDIUM] CWE-125 CVE-2018-6612: An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap
An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact.
nvdosv
CVE-2019-19035P4MEDIUMCVSS 5.5v3.032019-11-17
CVE-2019-19035 [MEDIUM] CWE-125 CVE-2019-19035: jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The compon
jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.
nvdosv
CVE-2019-1010302P4MEDIUMCVSS 5.5v3.032019-07-15
CVE-2019-1010302 [MEDIUM] CWE-119 CVE-2019-1010302: jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component
jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file.
nvdosv
1 / 2Next →