Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

56 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)0.30%—Google AndroidDebian LinuxCanonical Ubuntu LinuxLibexif Project Libexif+114/5/202017/6/2026
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9…
ModificadaMedia (5.5)0.53%—Libexif Project LibexifDebian LinuxCanonical Ubuntu LinuxOpensuse Leap9/5/202017/6/2026
exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
ModificadaAlta (7.5)3.8%—Libexif Project Libexif20/2/201917/6/2026
An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU resources.
ModificadaAlta (7.8)1.4%—Exiftool Project Exiftool2/1/201917/6/2026
ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with a victim's username, and then copying a Trojan horse ws32_32.dll file into this new folder, aka DLL Hijacking. NOTE: 8.32 is an obsolete version from 2010 (9.x was released starting in 2012, and 10.x…
ModificadaAlta (8.1)1.7%💥 PoCLibexif Project LibexifCanonical Ubuntu LinuxDebian Linux31/10/201817/6/2026
A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data).
ModificadaMedia (5.5)0.90%—Openexif Project Openexif30/9/201717/6/2026
ExifImageFile::readDQT in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted JPEG file.
ModificadaCrítica (9.1)3.3%—Libexif Project Libexif21/9/201717/6/2026
libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.
ModificadaMedia (5.5)0.93%—Openexif Project Openexif31/7/201717/6/2026
The ExifImageFile::readImage function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted jpg file.
ModificadaMedia (5.5)0.94%—Openexif Project Openexif31/7/201717/6/2026
The ExifImageFile::readDHT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.
ModificadaAlta (7.8)1.1%—Openexif Project Openexif31/7/201717/6/2026
The ExifImageFile::readDQT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.
ModificadaMedia (5.5)0.98%—Openexif Project Openexif31/7/201717/6/2026
The ExifJpegHUFFTable::deriveTable function in ExifHuffmanTable.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted jpg file.
ModificadaAlta (7.5)8.3%💥 ExploitTWO Pilots Exif Pilot27/1/201517/6/2026
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the maker element in an XML file.
ModificadaMedia (4.3)2.0%—HK Exif Tags Project HK Exif Tags13/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in the HK Exif Tags plugin before 1.12 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.4)3.6%—Curtis Galloway Exif13/7/201216/6/2026
Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.
ModificadaAlta (7.5)5.7%—Libexif Project Libexif13/7/201216/6/2026
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.
ModificadaAlta (7.5)5.0%—Libexif Project Libexif13/7/201216/6/2026
Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.
ModificadaMedia (5)3.9%—Libexif Project Libexif13/7/201216/6/2026
The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note…
ModificadaMedia (6.4)6.2%—Libexif Project Libexif13/7/201216/6/2026
The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.
ModificadaAlta (7.5)7.6%—Libexif Project Libexif13/7/201216/6/2026
Buffer overflow in the exif_entry_format_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.
ModificadaMedia (6.4)3.8%—Libexif Project Libexif13/7/201216/6/2026
The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.
ModificadaMedia (6.4)3.9%—Libexif Project Libexif13/7/201216/6/2026
The exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.
ModificadaMedia (6.8)5.1%—Libexif Project Libexif20/11/200916/6/2026
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.0%—Exif1/5/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.
ModificadaMedia (4.3)1.7%—Libexif Project Libexif20/12/200716/6/2026
libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c.
ModificadaMedia (6.8)2.7%—Libexif20/12/200716/6/2026
Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
Orbitaley — Vulnerabilidades