Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-27815

20
FAUCET Score

CVE-2021-27815 describes a NULL Pointer Dereference vulnerability in the exif command-line tool (versions 0.6.22 and earlier) when processing XML-formatted EXIF data. This flaw allows an attacker to trigger a Denial of Service by providing a specially crafted malicious JPEG file, causing the application to crash. Rated Medium severity (CVSS 5.5), it requires user interaction (UI:R) and local access (AV:L) to exploit, resulting in high availability impact (A:H). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.6.22CPE matchmatch criteria
cpe:2.3:a:libexif_project:exif:*:*:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.27%
Probability of exploitation in next 30 days
EPSS Percentile
66.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0127 is in the 77th percentile among its peer group of 5,765 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2021-27815Low

libexif: NULL Pointer Deference may lead to DoS by uploading a malicious JPEG file

Feb 25, 2021

References

github.com / libexif/exif/commit/eb84b0e3c5f2a86013b6fcfb800d187896a648fa
PatchThird Party Advisory
github.com / libexif/exif/commit/f6334d9d32437ef13dc902f0a88a2be0063d9d1c
PatchThird Party Advisory
github.com / libexif/exif/issues/4
ExploitThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/JSWAXZVNXYLV3E4R6YQTEGRGMGWEAR76
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QMC6OTXZRPCUD3LOSWO4ISR7CH7NJQDT
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YZQ3L45F7S7PQPG5HEHXOCGNOO64MJOS
security.gentoo.org / glsa/202210-28
Third Party Advisory