pkg:Debian/libexif

40 total CVEsCRITICAL5HIGH14MEDIUM4

✅ Check your installed version

All known vulnerabilities

  • CRITICAL9.8CVE-2020-0452libexif - security update
    from 0, < 0.6.22-3
  • CRITICAL9.8CVE-2020-0452libexif - security update
    from 0, < 0.6.21-2+deb9u5
  • CRITICAL9.8CVE-2020-0452libexif - security update
    from 0, < 0.6.21-5.1+deb10u5
  • CRITICAL9.1CVE-2020-13112An issue was discovered in libexif before 0.6.22.
    from 0, < 0.6.21-9
  • CRITICAL9.1CVE-2017-7544libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c…
    from 0, < 0.6.21-2.1
  • HIGH8.8CVE-2019-9278libexif - security update
    from 0, < 0.6.21-2+deb8u1
  • HIGH8.8CVE-2019-9278libexif - security update
    from 0, < 0.6.21-6
  • HIGH8.8CVE-2019-9278libexif - security update
    from 0, < 0.6.21-2+deb9u1
  • HIGH8.2CVE-2020-13113An issue was discovered in libexif before 0.6.22.
    from 0, < 0.6.21-9
  • HIGH8.1CVE-2016-6328libexif - security update
    from 0, < 0.6.21-2.1
  • HIGH8.1CVE-2016-6328libexif - security update
    from 0, < 0.6.21-2+deb8u2
  • HIGH7.8CVE-2026-32775libexif through 0.6.25 has a flaw in decoding MakerNotes.
    from 0, < 0.6.22-3+deb11u1
  • HIGH7.5CVE-2020-0198In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow.
    from 0, < 0.6.22-2
  • HIGH7.5CVE-2020-0181In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow.
    from 0, < 0.6.21-6
  • HIGH7.5CVE-2020-13114An issue was discovered in libexif before 0.6.22.
    from 0, < 0.6.21-9
  • HIGH7.5CVE-2018-20030libexif - security update
    from 0, < 0.6.21-2+deb8u3
  • HIGH7.5CVE-2018-20030libexif - security update
    from 0, < 0.6.21-5.1
  • HIGH7.1CVE-2026-40386In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to cras…
    from 0, < 0.6.22-3+deb11u1
  • HIGH7.1CVE-2026-40385In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes…
    from 0, < 0.6.22-3+deb11u1
  • MEDIUM6.5CVE-2020-0182libexif - security update
    from 0, < 0.6.21-2+deb8u4
  • MEDIUM6.5CVE-2020-0182libexif - security update
    from 0, < 0.6.22-1
  • MEDIUM5.5CVE-2020-12767exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
    from 0, < 0.6.21-7
  • MEDIUM5.0CVE-2020-0093In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check.
    from 0, < 0.6.21-8
  • CVE-2012-2841Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow rem…
    from 0, < 0.6.20-3
  • CVE-2012-2840Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 all…
    from 0, < 0.6.20-3
  • CVE-2012-2837The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 all…
    from 0, < 0.6.20-3
  • CVE-2012-2836The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to caus…
    from 0, < 0.6.20-3
  • CVE-2012-2814Buffer overflow in the exif_entry_format_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 allows remote…
    from 0, < 0.6.20-3
  • CVE-2012-2813The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers…
    from 0, < 0.6.20-3
  • CVE-2012-2812libexif - several
    from 0, < 0.6.19-1+squeeze1
  • CVE-2012-2812libexif - several
    from 0, < 0.6.20-3
  • CVE-2009-3895Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remo…
    from 0, < 0.6.19-1
  • CVE-2007-6351libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with craf…
    from 0, < 0.6.16-2.1
  • CVE-2007-6352Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF…
    from 0, < 0.6.16-2.1
  • CVE-2006-4168libexif
    from 0, < 0.6.16-1
  • CVE-2006-4168libexif
    from 0, < 0.6.13-5etch1
  • CVE-2007-2645libexif - several vulnerabilities
    from 0, < 0.6.9-6sarge2
  • CVE-2007-2645libexif - several vulnerabilities
    from 0, < 0.6.15-1
  • CVE-2005-0664libexif - buffer overflow
    from 0, < 0.5.0-1woody1
  • CVE-2005-0664libexif - buffer overflow
    from 0, < 0.6.9-5