Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.17% | — | Matthiaswandel JheadAI | 14/9/2026 | 15/9/2026 | A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An attack has to be approached locally. The… | |
| Aplazada | Baja (1.9) | 0.16% | — | Matthiaswandel JheadAI | 14/9/2026 | 14/9/2026 | A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The… | |
| Analizada | Alta (7.8) | 0.26% | — | Jhead Project Jhead | 30/5/2025 | 17/6/2026 | jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c. | |
| Aplazada | Media (6.3) | 0.73% | — | Matthiaswandel JheadAI | 22/3/2024 | 17/6/2026 | A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (7.8) | 0.36% | — | Matthiaswandel Jhead | 11/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS). | |
| Modificada | Crítica (9.8) | 1.1% | — | Jhead Project Jhead | 13/6/2023 | 17/6/2026 | Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer overflow problem when multiple `&i` or `&o`… | |
| Modificada | Alta (7.8) | 0.43% | — | Jhead Project JheadDebian Linux | 4/11/2022 | 17/6/2026 | jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u. | |
| Modificada | Alta (7.8) | 0.47% | — | Jhead Project JheadFedoraproject FedoraDebian Linux | 17/10/2022 | 17/6/2026 | Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option. | |
| Modificada | Alta (7.8) | 0.87% | — | Jhead Project Jhead | 23/3/2022 | 17/6/2026 | A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c. | |
| Modificada | Alta (7.8) | 0.87% | — | Jhead Project Jhead | 23/3/2022 | 17/6/2026 | A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c. | |
| Modificada | Alta (7.5) | 1.1% | — | Jhead Project Jhead | 23/3/2022 | 17/6/2026 | A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c. | |
| Modificada | Media (5.5) | 0.66% | — | Jhead Project Jhead | 23/3/2022 | 17/6/2026 | A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file. | |
| Modificada | Media (6.1) | 0.89% | — | Jhead Project Jhead | 2/2/2022 | 17/6/2026 | JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images from digital cameras. In affected versions there is a heap-buffer-overflow on jhead-3.04/jpgfile.c:285 ReadJpegSections. Crafted jpeg images can be provided to the user resulting in a program crash or… | |
| Modificada | Alta (7.8) | 1.1% | — | Jhead Project Jhead | 22/4/2021 | 17/6/2026 | A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file. | |
| Modificada | Alta (7.1) | 1.4% | — | Jhead Project Jhead | 9/1/2020 | 17/6/2026 | jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c. | |
| Modificada | Alta (7.1) | 1.4% | — | Jhead Project Jhead | 9/1/2020 | 17/6/2026 | jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c. | |
| Modificada | Media (5.5) | 1.0% | — | Jhead Project Jhead | 17/11/2019 | 17/6/2026 | jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file. | |
| Modificada | Media (5.5) | 0.97% | — | Jhead Project JheadFedoraproject FedoraDebian Linux | 15/7/2019 | 17/6/2026 | jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file. | |
| Modificada | Media (5.5) | 1.2% | — | Jhead Project JheadFedoraproject FedoraDebian Linux | 15/7/2019 | 17/6/2026 | jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file. | |
| Modificada | Alta (7.8) | 1.6% | — | Jhead Project Jhead | 16/9/2018 | 17/6/2026 | The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data length. This is analogous to the… | |
| Modificada | Alta (7.8) | 1.8% | — | Jhead Project Jhead | 16/9/2018 | 17/6/2026 | The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling. | |
| Modificada | Media (5.5) | 1.1% | — | Jhead Project Jhead | 4/2/2018 | 17/6/2026 | An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact. | |
| Modificada | Alta (10) | 2.2% | — | Sentex Jhead | 21/10/2008 | 16/6/2026 | The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input. | |
| Modificada | Baja (3.6) | 0.30% | — | Sentex Jhead | 21/10/2008 | 16/6/2026 | The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character. | |
| Modificada | Media (4.6) | 0.32% | — | Sentex Jhead | 21/10/2008 | 16/6/2026 | jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file. |