Jhead

Vendor:

First CVE: Feb 4, 2018 · Active for 8 years

18
Total CVEs
More Total CVEs than 93% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jhead over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2018
8 years ago
Most Recent CVE
May 30, 2025
421 days ago

CVE Severity & Scoring

Jhead18 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local16 (88.9%)
Network2 (11.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (11.1%)
Unknown0 (0.0%)
Required16 (88.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None18 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhe
Jun 13, 20239.830NONO
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
Oct 17, 20227.826NONO
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG fil
Sep 16, 20187.826NONO
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
Nov 4, 20227.825NONO
A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
Mar 23, 20227.825NONO
A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.
Mar 23, 20227.825NONO
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG fil
Sep 16, 20187.825NONO
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.
Mar 23, 20227.524NONO
A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.
Apr 22, 20217.824NONO
jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
Jan 9, 20207.124NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Jhead

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0817.80.2%00
3.06.0.117.80.4%00
3.0638.50.9%00
3.0547.20.9%00
3.0447.20.9%00
3.0335.51.1%00
3.0027.81.7%00
3.015.51.1%00