CVE Tools

EXIV2

125 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for EXIV2, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

EXIV2 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
EXIV2 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-030
2025-040
2025-050
2025-060
2025-070
2025-082
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-033
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 125 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical22%
  • High2419%
  • Medium9576%
  • Low43%

Latest CVEs

The 15 most recently published vulnerabilities affecting EXIV2.

  1. CVE-2026-25884Exiv2: Out-of-bounds read in CrwMap::decode0x08058.1
  2. CVE-2026-27596Exiv2: Integer Underflow in LoaderNative::getData() Causes Heap Buffer Overflow7.5
  3. CVE-2026-27631Exiv2: Uncaught exception - cannot create std::vector larger than max_size()5.3
  4. CVE-2025-55304Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata5.5
  5. CVE-2025-54080Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file5.5
  6. CVE-2025-26623Use After Free in Exiv29.8
  7. CVE-2024-39695Exiv2 has an out-of-bounds read in AsfVideo::streamProperties5.3
  8. CVE-2024-24826Out-of-bounds read in QuickTimeVideo::NikonTagsDecoder in Exiv25.5
  9. CVE-2024-25112Denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder in Exiv25.5
  10. CVE-2023-44398Out-of-bounds write in exiv28.8
  11. CVE-2020-18831Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file.7.8
  12. CVE-2020-18773An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.6.5
  13. CVE-2020-18771Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.8.1
  14. CVE-2020-18774A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.6.5
  15. CVE-2020-18898A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store