Jhead
This hub aggregates every CVE we track for Jhead. Use it to gauge the current risk picture and drill into individual advisories.
other
25
CVEs tracked
2
Critical
12
High
0
In CISA KEV
Severity distribution
HIGH12MEDIUM10CRITICAL2LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Jhead.
- CVE-2025-44906jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.7.8
- CVE-2024-2824Matthias-Wandel jhead exif.c PrintFormatNumber heap-based overflow6.3
- CVE-2020-28840Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).7.8
- CVE-2022-28550Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check...9.8
- CVE-2021-34055jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.7.8
- CVE-2022-41751Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.7.8
- CVE-2021-28275A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.5.5
- CVE-2021-28277A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.7.8
- CVE-2021-28276A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.7.5
- CVE-2021-28278A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.7.8
- CVE-2020-26208Heap-buffer-overflow in jhead5.3
- CVE-2021-3496A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.7.8
- BDU:2021-00678Уязвимость функции Get16m (jpgfile.c) программного средства для работы с EXIF-файлами jhead, позволяющая нарушителю вызвать отказ в обслуживании4.3
- CVE-2020-6624jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.7.1
- CVE-2020-6625jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.7.1
Product normalization is registry-driven with AI assist and human review. How it works