← Vulnerability feed

Vulnerability record · CVE-2012-2840 · published 13 July 2012

CVE-2012-2840: Libexif project libexif vulnerability

LLibexif Project · Libexif

Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.

7.5 CVSS 2.0 High EPSS 5.0% · top 8.0% CWE-189 · CWE-189
7.5CVSS 2.0 base score
5.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2840 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2020-13112Libexif project libexif out-of-bounds read vulnerabilityAn issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crash…EPSS 2.7%9.1CVE-2017-7544Libexif project libexif out-of-bounds read vulnerabilitylibexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by …EPSS 3.3%8.2CVE-2020-13113Libexif project libexif use of uninitialized resource vulnerabilityAn issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-afte…EPSS 1.9%8.1CVE-2016-6328Libexif project libexif integer overflow vulnerabilityA vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS)…EPSS 1.7%7.8CVE-2026-32775Libexif project libexif vulnerabilitylibexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer wou…EPSS 0.16%7.5CVE-2020-0198Google android integer overflow vulnerabilityIn exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of servic…EPSS 4.3%7.5CVE-2020-0181Google android integer overflow vulnerabilityIn exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial o…EPSS 2.9%7.5CVE-2020-13114Libexif project libexif allocation without limits vulnerabilityAn issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amoun…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2012-2840), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.