Openexif Project maintains a narrowly scoped image metadata parsing library whose role in downstream tools and applications gives it relevance beyond its small disclosure volume. The recurring vulnerabilities center on memory-safety and control-flow weaknesses—out-of-bounds reads, buffer-boundary violations, and infinite-loop conditions—that are characteristic of low-level image format parsing where malformed EXIF data can trigger parsing faults. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openexif Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11116HIGH The ExifImageFile::readDQT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application cra | Jul 31, 2017 | 7.8 | 20 | NO | NO |
CVE-2017-14931MEDIUM ExifImageFile::readDQT in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a cr | Sep 30, 2017 | 5.5 | 19 | NO | NO |
CVE-2017-11118MEDIUM The ExifImageFile::readImage function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a craf | Jul 31, 2017 | 5.5 | 16 | NO | NO |
CVE-2017-11117MEDIUM The ExifImageFile::readDHT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application cra | Jul 31, 2017 | 5.5 | 16 | NO | NO |
CVE-2017-11115MEDIUM The ExifJpegHUFFTable::deriveTable function in ExifHuffmanTable.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and applicati | Jul 31, 2017 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openexif Project.
Media articles that mention a CVE ID that affects a product developed by Openexif Project — matched by CVE ID, not by vendor name.