📦 Exiv2

by Exiv2

🔍 What is Exiv2?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-26623

CRITICAL CVSS 9.8 Feb 18, 2025

A heap buffer overflow vulnerability in Exiv2 versions 0.28.0 through 0.28.4 allows attackers to potentially execute arbitrary code by tricking victims into processing a crafted image file with metada...

CVE-2023-44398

HIGH CVSS 8.8 Nov 6, 2023

CVE-2023-44398 is an out-of-bounds write vulnerability in Exiv2 v0.28.0 that allows remote code execution when processing a malicious image file. Attackers can exploit this by tricking users into open...

CVE-2020-18831

HIGH CVSS 7.8 Aug 22, 2023

A buffer overflow vulnerability in Exiv2's PNG processing allows remote attackers to cause denial of service or potentially execute arbitrary code by providing a specially crafted PNG file. This affec...

CVE-2020-18771

HIGH CVSS 8.1 Aug 23, 2021

This vulnerability in Exiv2 image metadata library allows attackers to read beyond allocated memory boundaries when processing specially crafted Nikon image files. This can lead to information disclos...

CVE-2021-31292

HIGH CVSS 7.5 Jul 26, 2021

This CVE describes an integer overflow vulnerability in Exiv2's CrwMap::encode0x1810 function that allows attackers to trigger a heap-based buffer overflow via crafted metadata. Attackers can cause de...

CVE-2025-54080

MEDIUM CVSS 5.5 Aug 29, 2025

CVE-2025-54080 is an out-of-bounds read vulnerability in Exiv2 library versions 0.28.5 and earlier. An attacker can cause denial of service by crashing Exiv2 when it writes metadata to a specially cra...