CVE-2026-40386
- EPSS 0.14%
- Veröffentlicht 12.04.2026 18:19:08
- Zuletzt bearbeitet 14.04.2026 20:43:44
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
CVE-2026-40385
- EPSS 0.09%
- Veröffentlicht 12.04.2026 18:16:30
- Zuletzt bearbeitet 14.04.2026 20:15:39
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
CVE-2026-32775
- EPSS 0.19%
- Veröffentlicht 16.03.2026 06:31:36
- Zuletzt bearbeitet 21.04.2026 13:54:31
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
CVE-2007-6352
- EPSS 2.73%
- Veröffentlicht 20.12.2007 02:46:00
- Zuletzt bearbeitet 16.06.2026 22:47:53
Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
CVE-2006-4168
- EPSS 4.3%
- Veröffentlicht 14.06.2007 19:30:00
- Zuletzt bearbeitet 16.06.2026 22:28:32
Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, whic...
CVE-2007-2645
- EPSS 13.16%
- Veröffentlicht 14.05.2007 21:19:00
- Zuletzt bearbeitet 16.06.2026 22:40:01
Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1) ...
CVE-2005-0664
- EPSS 4.46%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:11:32
Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a ...