Jhead
Vendor:
First CVE: Feb 4, 2018 · Active for 8 years
18
Total CVEs
More Total CVEs than 93% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jhead over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2018
8 years ago
Most Recent CVE
May 30, 2025
421 days ago
CVE Severity & Scoring
Jhead18 CVEs
33%
61%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local16 (88.9%)
Network2 (11.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (11.1%)
Unknown0 (0.0%)
Required16 (88.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None18 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28550CRITICAL Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhe | Jun 13, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-41751HIGH Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option. | Oct 17, 2022 | 7.8 | 26 | NO | NO |
CVE-2018-16554HIGH The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG fil | Sep 16, 2018 | 7.8 | 26 | NO | NO |
CVE-2021-34055HIGH jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u. | Nov 4, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-28278HIGH A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c. | Mar 23, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-28277HIGH A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c. | Mar 23, 2022 | 7.8 | 25 | NO | NO |
CVE-2018-17088HIGH The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG fil | Sep 16, 2018 | 7.8 | 25 | NO | NO |
CVE-2021-28276HIGH A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c. | Mar 23, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-3496HIGH A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file. | Apr 22, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-6624HIGH jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c. | Jan 9, 2020 | 7.1 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Jhead
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.08 | 1 | 7.8 | 0.2% | 0 | 0 |
| 3.06.0.1 | 1 | 7.8 | 0.4% | 0 | 0 |
| 3.06 | 3 | 8.5 | 0.9% | 0 | 0 |
| 3.05 | 4 | 7.2 | 0.9% | 0 | 0 |
| 3.04 | 4 | 7.2 | 0.9% | 0 | 0 |
| 3.03 | 3 | 5.5 | 1.1% | 0 | 0 |
| 3.00 | 2 | 7.8 | 1.7% | 0 | 0 |
| 3.0 | 1 | 5.5 | 1.1% | 0 | 0 |