Jhead Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 18
    Known Exploited: 0
    1
    Critical Level Threats
    11
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-44906

    jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.

    Last Modified: Jun 19, 2025
    Published: May 30, 2025

    CVE-2022-28550

    Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer overflow problem when multiple `&i` or `&o` are given.

    Last Modified: Jan 03, 2025
    Published: Jun 13, 2023

    CVE-2021-34055

    jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.

    Last Modified: May 02, 2025
    Published: Nov 04, 2022

    CVE-2022-41751

    Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.

    Last Modified: May 13, 2025
    Published: Oct 17, 2022

    CVE-2021-28275

    A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.

    Last Modified: Nov 21, 2024
    Published: Mar 23, 2022
    Items Per Page
    Jhead_Project Vulnerabilities & Security CVEs | CVE-DB