Jhead Project Jhead vulnerabilities
24 known vulnerabilities affecting jhead_project/jhead.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH13MEDIUM8LOW1
Vulnerabilities
Page 2 of 2
CVE-2008-4575P4MEDIUMCVSS 5.0≥ 0, < 2.84-12008-10-15
CVE-2008-4575 [MEDIUM] CVE-2008-4575: Buffer overflow in the DoCommand function in jhead before 2
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
osv
CVE-2021-28275P4MEDIUMCVSS 5.5v3.04v3.052022-03-23
CVE-2021-28275 [MEDIUM] CWE-704 CVE-2021-28275: A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Ge
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.
nvdosv
CVE-2008-4639P4MEDIUMCVSS 4.6≥ 0, < 2.84-12008-10-21
CVE-2008-4639 [MEDIUM] CVE-2008-4639: jhead
jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
osv
CVE-2008-4640P4LOWCVSS 3.6≥ 0, < 2.85-12008-10-21
CVE-2008-4640 [LOW] CVE-2008-4640: The DoCommand function in jhead
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.
osv
← Previous2 / 2