Jhead-project
6 CVEs tracked since 2018. Since Sep 2018, none of them reached CISA KEV.
Jhead-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2018-09 | 2 | 0 |
| 2018-10 | null or fewer | |
| 2018-11 | null or fewer | |
| 2018-12 | null or fewer | |
| 2019-01 | null or fewer | |
| 2019-02 | null or fewer | |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | null or fewer | |
| 2019-06 | null or fewer | |
| 2019-07 | null or fewer | |
| 2019-08 | null or fewer | |
| 2019-09 | null or fewer | |
| 2019-10 | null or fewer | |
| 2019-11 | null or fewer | |
| 2019-12 | null or fewer | |
| 2020-01 | null or fewer | |
| 2020-02 | null or fewer | |
| 2020-03 | null or fewer | |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | null or fewer | |
| 2020-07 | null or fewer | |
| 2020-08 | null or fewer | |
| 2020-09 | null or fewer | |
| 2020-10 | null or fewer | |
| 2020-11 | null or fewer | |
| 2020-12 | null or fewer | |
| 2021-01 | null or fewer | |
| 2021-02 | null or fewer | |
| 2021-03 | null or fewer | |
| 2021-04 | null or fewer | |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | null or fewer | |
| 2021-11 | null or fewer | |
| 2021-12 | null or fewer | |
| 2022-01 | null or fewer | |
| 2022-02 | null or fewer | |
| 2022-03 | 4 | 0 |
Products
The products that kept showing up in Jhead-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Jhead-project.
- CVE-2025-44906jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.7.8
- CVE-2022-28550Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check...9.8
- CVE-2021-34055jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.7.8
- CVE-2022-41751Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.7.8
- CVE-2021-28277A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.7.8
- CVE-2021-28275A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.5.5
- CVE-2021-28278A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.7.8
- CVE-2021-28276A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.7.5
- CVE-2020-26208Heap-buffer-overflow in jhead5.3
- CVE-2021-3496A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.7.8
- CVE-2020-6625jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.7.1
- CVE-2020-6624jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.7.1
- CVE-2019-19035jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially cr...5.5
- CVE-2019-1010301jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.5.5
- CVE-2019-1010302jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted ...5.5
The record
- Peak rank
- #145 in Mar 2022
- Busiest month shown
- Mar 2022, 4 CVEs
- Months with a KEV entry
- 0 since Sep 2018
- Monthly snapshots
- 2 since 2018