Libexif Project
Libexif Project Libexif: vulnerabilidades y CVE
Libexif Project Libexif tiene 22 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses3
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40386 | Alta (7.1) | 0.13% | — | 12 abr 2026 | In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs. |
| CVE-2026-40385 | Alta (7.1) | 0.13% | — | 12 abr 2026 | In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems. |
| CVE-2026-32775 | Alta (7.8) | 0.16% | — | 16 mar 2026 | libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow. |
| CVE-2020-0198 | Alta (7.5) | 4.3% | — | 11 jun 2020 | In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is… |
| CVE-2020-0181 | Alta (7.5) | 2.9% | — | 11 jun 2020 | In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User… |
| CVE-2020-13113 | Alta (8.2) | 1.9% | — | 21 may 2020 | An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions. |
| CVE-2020-13114 | Alta (7.5) | 2.3% | — | 21 may 2020 | An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data. |
| CVE-2020-13112 | Crítica (9.1) | 2.7% | — | 21 may 2020 | An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093. |
| CVE-2020-0093 | Media (5) | 0.30% | — | 14 may 2020 | In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User… |
| CVE-2020-12767 | Media (5.5) | 0.53% | — | 9 may 2020 | exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error. |
| CVE-2018-20030 | Alta (7.5) | 3.8% | — | 20 feb 2019 | An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU resources. |
| CVE-2016-6328 | Alta (8.1) | 1.7% | — | 31 oct 2018 | A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk… |
| CVE-2017-7544 | Crítica (9.1) | 3.3% | — | 21 sept 2017 | libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote… |
| CVE-2012-2841 | Alta (7.5) | 5.7% | — | 13 jul 2012 | Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted… |
| CVE-2012-2840 | Alta (7.5) | 5.0% | — | 13 jul 2012 | Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary… |
| CVE-2012-2837 | Media (5) | 3.9% | — | 13 jul 2012 | The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an… |
| CVE-2012-2836 | Media (6.4) | 6.2% | — | 13 jul 2012 | The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive… |
| CVE-2012-2814 | Alta (7.5) | 7.6% | — | 13 jul 2012 | Buffer overflow in the exif_entry_format_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 allows remote attackers to cause a denial of service or possibly execute arbitrary code via… |
| CVE-2012-2813 | Media (6.4) | 3.8% | — | 13 jul 2012 | The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive… |
| CVE-2012-2812 | Media (6.4) | 3.9% | — | 13 jul 2012 | The exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive… |
| CVE-2009-3895 | Media (6.8) | 5.1% | — | 20 nov 2009 | Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via… |
| CVE-2007-6351 | Media (4.3) | 1.7% | — | 20 dic 2007 | libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in… |