Known Vulnerabilities for products from Jhead Project
Listed below are 17 of the newest known vulnerabilities associated with the vendor "Jhead Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-41751 json | Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regene... | 7.8 - HIGH | 2022-10-17 | 2023-11-07 |
| CVE-2022-28550 json | Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to ... | 9.8 - CRITICAL | 2023-06-13 | 2023-06-23 |
| CVE-2021-34055 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.8 - HIGH | 2022-11-04 | 2023-02-03 |
| CVE-2021-28278 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.8 - HIGH | 2022-03-23 | 2022-11-16 |
| CVE-2021-28277 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.8 - HIGH | 2022-03-23 | 2022-11-16 |
| CVE-2021-28276 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2022-03-23 | 2022-11-16 |
| CVE-2021-28275 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.5 - MEDIUM | 2022-03-23 | 2022-11-16 |
| CVE-2021-3496 json | A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file. | 7.8 - HIGH | 2021-04-22 | 2022-12-21 |
| CVE-2020-26208 json | JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images from dig... | 6.1 - MEDIUM | 2022-02-02 | 2022-02-07 |
| CVE-2020-6625 json | jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c. | 7.1 - HIGH | 2020-01-09 | 2022-11-08 |
| CVE-2020-6624 json | jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c. | 7.1 - HIGH | 2020-01-09 | 2022-11-08 |
| CVE-2019-1010302 json | jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show... | 5.5 - MEDIUM | 2019-07-15 | 2023-11-07 |
| CVE-2019-1010301 json | jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGps... | 5.5 - MEDIUM | 2019-07-15 | 2023-11-07 |
| CVE-2019-19035 json | jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections ... | 5.5 - MEDIUM | 2019-11-17 | 2023-11-07 |
| CVE-2018-17088 json | The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service atta... | 7.8 - HIGH | 2018-09-16 | 2019-12-31 |
| CVE-2018-16554 json | The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service atta... | 7.8 - HIGH | 2018-09-16 | 2019-12-31 |
| CVE-2018-6612 json | An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read w... | 5.5 - MEDIUM | 2018-02-04 | 2020-08-24 |
Known software with vulnerabilities from Jhead Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Jhead Project | Jhead | 1.2 |