Aertherwide maintains a niche image-processing utility, exiftags, that handles EXIF metadata extraction and manipulation in image files. The reported vulnerabilities center on memory-safety issues including out-of-bounds writes and heap-based buffer overflows, typical of C-based parsers handling variable-length binary metadata formats. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aertherwide over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6354HIGH Unspecified vulnerability in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a differ | Dec 18, 2007 | 10.0 | 27 | NO | NO |
CVE-2007-6355HIGH Integer overflow in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulne | Dec 18, 2007 | 10.0 | 25 | NO | NO |
CVE-2024-42851HIGH Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function. | Aug 27, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-50671HIGH In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected address. | Jan 11, 2024 | 7.8 | 22 | NO | NO |
CVE-2007-6356MEDIUM exiftags before 1.01 allows attackers to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image. | Dec 18, 2007 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aertherwide.
Media articles that mention a CVE ID that affects a product developed by Aertherwide — matched by CVE ID, not by vendor name.