EXIV2
125 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for EXIV2, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
EXIV2 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 2 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 3 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 125 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High24
- Medium95
- Low4
Latest CVEs
The 15 most recently published vulnerabilities affecting EXIV2.
- CVE-2026-25884Exiv2: Out-of-bounds read in CrwMap::decode0x08058.1
- CVE-2026-27596Exiv2: Integer Underflow in LoaderNative::getData() Causes Heap Buffer Overflow7.5
- CVE-2026-27631Exiv2: Uncaught exception - cannot create std::vector larger than max_size()5.3
- CVE-2025-55304Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata5.5
- CVE-2025-54080Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file5.5
- CVE-2025-26623Use After Free in Exiv29.8
- CVE-2024-39695Exiv2 has an out-of-bounds read in AsfVideo::streamProperties5.3
- CVE-2024-24826Out-of-bounds read in QuickTimeVideo::NikonTagsDecoder in Exiv25.5
- CVE-2024-25112Denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder in Exiv25.5
- CVE-2023-44398Out-of-bounds write in exiv28.8
- CVE-2020-18831Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file.7.8
- CVE-2020-18773An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.6.5
- CVE-2020-18771Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.8.1
- CVE-2020-18774A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.6.5
- CVE-2020-18898A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.6.5
Product grouping is registry-driven, with AI assist and human review. How it works