5
CVSSv2

CVE-2005-4676

Published: 31/12/2005 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in Andreas Huggel Exiv2 prior to 0.9 does not null terminate strings before calling the sscanf function, which allows remote malicious users to cause a denial of service (application crash) via images with crafted IPTC metadata.

Vulnerable Product Search on Vulmon Subscribe to Product

andreas huggel exiv2 0.4

andreas huggel exiv2 0.5

andreas huggel exiv2 0.6.2

andreas huggel exiv2 0.7

andreas huggel exiv2 0.3

andreas huggel exiv2 0.8

andreas huggel exiv2 0.6

andreas huggel exiv2 0.6.1

Exploits

source: wwwsecurityfocuscom/bid/16400/info Exiv2 is susceptible to a denial-of-service vulnerability This issue is due to the application's failure to properly bounds-check user-supplied input data before attempting to read it, resulting in an out-of-bounds memory access crash This issue allows attackers to crash applications that use ...