Jhead Project maintains a lightweight JPEG image metadata editor and manipulation tool that, despite its narrow product scope, ranks among the more prominent tools in its category and is distributed across Linux systems, embedded devices, and photography workflows. The vendor's vulnerability footprint centers on memory-safety and command-handling weaknesses characteristic of C-based image parsers: out-of-bounds writes and reads, classic buffer overflows, and OS command injection, reflecting the parsing complexity inherent to EXIF and JPEG structure handling. A meaningful share of the vendor's disclosures reach serious severity; live exploitation activity, public exploit availability, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jhead Project over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28550CRITICAL Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhe | Jun 13, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-41751HIGH Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option. | Oct 17, 2022 | 7.8 | 26 | NO | NO |
CVE-2018-16554HIGH The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG fil | Sep 16, 2018 | 7.8 | 26 | NO | NO |
CVE-2021-34055HIGH jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u. | Nov 4, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-28278HIGH A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c. | Mar 23, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-28277HIGH A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c. | Mar 23, 2022 | 7.8 | 25 | NO | NO |
CVE-2018-17088HIGH The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG fil | Sep 16, 2018 | 7.8 | 25 | NO | NO |
CVE-2021-28276HIGH A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c. | Mar 23, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-3496HIGH A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file. | Apr 22, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-6624HIGH jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c. | Jan 9, 2020 | 7.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jhead Project.
Media articles that mention a CVE ID that affects a product developed by Jhead Project — matched by CVE ID, not by vendor name.