Summary
Detail | |||
---|---|---|---|
Vendor | Aertherwide | First view | 2007-12-18 |
Product | Exiftags | Last view | 2024-08-27 |
Version | 0.92 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:aertherwide:exiftags |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
7.8 | 2024-08-27 | CVE-2024-42851 | Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function. |
5 | 2007-12-18 | CVE-2007-6356 | exiftags before 1.01 allows attackers to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image. |
10 | 2007-12-18 | CVE-2007-6355 | Integer overflow in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6354. |
10 | 2007-12-18 | CVE-2007-6354 | Unspecified vulnerability in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6355. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
33% (1) | CWE-787 | Out-of-bounds Write |
33% (1) | CWE-399 | Resource Management Errors |
33% (1) | CWE-189 | Numeric Errors |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
42648 | exiftags Unspecified Field Offset Overflow #1 |
42647 | exiftags JPEG Handling EXIF Data IFD References Recursion DoS |
42646 | exiftags Unspecified Field Offset Overflow #2 |
OpenVAS Exploits
id | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200712-17 (exiftags) File : nvt/glsa_200712_17.nasl |
2008-04-07 | Name : Debian Security Advisory DSA 1533-1 (exiftags) File : nvt/deb_1533_1.nasl |
2008-04-07 | Name : Debian Security Advisory DSA 1533-2 (exiftags) File : nvt/deb_1533_2.nasl |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2008-03-31 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-1533.nasl - Type: ACT_GATHER_INFO |
2007-12-31 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-200712-17.nasl - Type: ACT_GATHER_INFO |