Jhead Project

Jhead

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Veröffentlicht 22.04.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:21:40

A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.

Exploit
  • EPSS 0.85%
  • Veröffentlicht 09.01.2020 01:15:16
  • Zuletzt bearbeitet 21.11.2024 05:36:03

jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.

Exploit
  • EPSS 1.01%
  • Veröffentlicht 09.01.2020 01:15:16
  • Zuletzt bearbeitet 21.11.2024 05:36:03

jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.

Exploit
  • EPSS 0.17%
  • Veröffentlicht 17.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:02

jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 15.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:08

jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 15.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:08

jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 16.09.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:51

The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a l...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 16.09.2018 02:29:00
  • Zuletzt bearbeitet 21.11.2024 03:52:58

The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf form...

  • EPSS 0.16%
  • Veröffentlicht 04.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:59

An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified ot...