The Metadataextractor Project maintains a specialized library for extracting metadata from image and document files, a focused component with narrow distribution but used in file-processing pipelines across media and document-handling applications. Its observed vulnerability pattern centers on resource-consumption weaknesses, reflecting the parsing demands of handling untrusted file formats. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Metadataextractor Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14262HIGH MetadataExtractor 2.1.0 allows stack consumption. | Jul 25, 2019 | 7.5 | 23 | NO | NO |
CVE-2022-24614MEDIUM When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for ve | Feb 24, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-24613MEDIUM metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to | Feb 24, 2022 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Metadataextractor Project.
Media articles that mention a CVE ID that affects a product developed by Metadataextractor Project — matched by CVE ID, not by vendor name.