CVE-2019-14368 is a high-severity heap-based buffer over-read vulnerability in Exiv2 versions 0.27.99.0 and earlier, specifically within the Exiv2::RafImage::readMetadata() function. This flaw could allow an unauthenticated attacker to achieve high impact to confidentiality, integrity, and availability through local access and user interaction. Despite its high CVSS score of 7.8, there is no known public exploit code, Metasploit modules, or Nuclei templates available. Furthermore, the vulnerability has garnered minimal community discussion and media coverage, suggesting a low level of public awareness and active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.27.99.0CPE matchmatch criteria | cpe:2.3:a:exiv2:exiv2:0.27.99.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.