Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-6351

16
FAUCET Score

CVE-2007-6351 describes a denial-of-service vulnerability in libexif versions 0.6.16 and earlier, where a specially crafted image file with malicious EXIF tags can trigger an infinite recursion. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and a partial availability impact, meaning it can disrupt service but not compromise data or systems. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.6.16CPE matchmatch criteria
cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*
0.6.14CPE matchmatch criteria
cpe:2.3:a:libexif_project:libexif:0.6.14:*:*:*:*:*:*:*
0.6.15CPE matchmatch criteria
cpe:2.3:a:libexif_project:libexif:0.6.15:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.68%
Probability of exploitation in next 30 days
EPSS Percentile
74.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0168 is in the 51st percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: libexif-0:0.6.13-4.0.2.el5_1.1
View patch

Vendor Advisories (1)

redhatCVE-2007-6351Moderate

libexif infinite recursion flaw (DoS)

Dec 14, 2007

References

bugs.gentoo.org / show_bug.cgi
osvdb.org / 42652
bugzilla.redhat.com / show_bug.cgi
bugzilla.redhat.com / show_bug.cgi
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/28076
Vendor Advisory
secunia.com / advisories/28127
Vendor Advisory
secunia.com / advisories/28195
Vendor Advisory
secunia.com / advisories/28266
Vendor Advisory
secunia.com / advisories/28346
Vendor Advisory
secunia.com / advisories/28400
Vendor Advisory
secunia.com / advisories/28636
Vendor Advisory
secunia.com / advisories/28776
Vendor Advisory
secunia.com / advisories/32274
Vendor Advisory
security.gentoo.org / glsa/glsa-200712-15.xml
exchange.xforce.ibmcloud.com / vulnerabilities/39166
issues.rpath.com / browse/RPL-2068
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9420
redhat.com / archives/fedora-package-announce/2007-December/msg00597.html
redhat.com / archives/fedora-package-announce/2007-December/msg00626.html
debian.org / security/2008/dsa-1487
mandriva.com / security/advisories
novell.com / linux/security/advisories/suse_security_summary_report.html
redhat.com / support/errata/RHSA-2007-1165.html
Patch
securityfocus.com / archive/1/485822/100/0/threaded
securityfocus.com / bid/26976
securitytracker.com / id
ubuntu.com / usn/usn-654-1
vupen.com / english/advisories/2007/4278
Vendor Advisory