exiv2
Low level Python interface to the Exiv2 C++ library.
Activity
- Latest release
- 2w ago
- Total releases
- 33
- Cadence
- ~34 days
- Last 12 months
- 5
Reach
- Stars
- 25
Details
- License
- unknown
- First release
- Feb 25, 2018
| Version | Released | |
|---|---|---|
0.19.2
patch
9 CVEs
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.19.1
patch
9 CVEs
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.19.0
minor
9 CVEs
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.18.1
patch
9 CVEs
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.18.0
minor
9 CVEs
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.17.5
patch
9 CVEs
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.17.4
patch
9 CVEs
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.17.3
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.17.2
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.17.1
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.17.0
minor
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.16.2.post1
pre
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.16.3.post1
pre
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.16.3
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.16.2
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.16.1
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.16.0
minor
13 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-25112
GHSA-crmj-qh74-2r36
PYSEC-2024-107
Oct 17, 2024
Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
ImpactA denial-of-service was found in Exiv2 version v0.28.1: an unbounded recursion can cause Exiv2 to crash by exhausting the stack. The vulnerable function, PatchesThe bug is fixed in version v0.28.2. For more informationPlease see our security policy for information about Exiv2 security. CreditThis bug was found by OSS-Fuzz. Affected versions
0.16.0
Fixed in
0.16.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-24826
GHSA-g9xm-7538-mq8w
PYSEC-2024-106
Oct 17, 2024
Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
ImpactAn out-of-bounds read was found in Exiv2 version v0.28.1. The vulnerable function, PatchesThe bug is fixed in version v0.28.2. For more informationPlease see our security policy for information about Exiv2 security. CreditThis bug was found by OSS-Fuzz. Affected versions
0.16.0
Fixed in
0.16.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.15.0
minor
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.14.1
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.14.0
minor
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.13.2
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.13.1
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.13.0
minor
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.12.1
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.12.0
minor
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.11.3
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.11.2
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.11.1
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.11.0
minor
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.3.1
patch
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.3
minor
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.2
minor
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev | ||
0.1
initial
11 CVEs
CVE-2025-55304
PYSEC-2026-1355
GHSA-m54q-mm9w-fp6g
Jul 07, 2026
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Medium
Local
Low
None
ImpactA denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in PatchesThe bug is fixed in version v0.28.6. ReferencesIssue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch) For more informationPlease see our security policy for information about Exiv2 security. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-54080
PYSEC-2026-1354
GHSA-496f-x7cq-cq39
Jul 07, 2026
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Medium
Local
Low
None
ImpactAn out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete. PatchesThe bug is fixed in version v0.28.6. CreditThank you to @dragonArthurX for reporting this issue. Details (from original report by @dragonArthurX )Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f Platform: Ubuntu 20.04.6 LTS (x86_64) Build Steps:
Command line to reproduce:
Crash Output:
Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 14 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.2
0.3
0.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-44398
PYSEC-2023-233
GHSA-hrw9-ggg3-3r4r
Nov 06, 2023
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18831
PYSEC-2023-150
Aug 22, 2023
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2020-18899
PYSEC-2021-879
Aug 19, 2021
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.2
0.3
0.3.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2021-31292
PYSEC-2021-877
Jul 26, 2021
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20098
PYSEC-2018-119
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20099
PYSEC-2018-120
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20096
PYSEC-2018-117
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-20097
PYSEC-2018-118
Dec 12, 2018
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2017-9239
PYSEC-2017-112
May 26, 2017
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file. Affected versions
0.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
+ 16 more Show less
0.2
0.3
0.3.1
0.15.0
0.16.0
0.16.1
0.16.2
0.16.2.post1
0.16.3
0.16.3.post1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
References Updated Oct 09, 2025 · Source: OSV.dev |