← Vulnerability feed

Vulnerability record · CVE-2017-7544 · published 21 September 2017

CVE-2017-7544: Libexif project libexif out-of-bounds read vulnerability

LLibexif Project · Libexif

libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.

9.1 CVSS 3.0 Critical EPSS 3.3% · top 12.0% CWE-125 · Out-of-bounds read
9.1CVSS 3.0 base score, v2 6.4
3.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-7544 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2020-13112Libexif project libexif out-of-bounds read vulnerabilityAn issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crash…EPSS 2.7%8.2CVE-2020-13113Libexif project libexif use of uninitialized resource vulnerabilityAn issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-afte…EPSS 1.9%8.1CVE-2016-6328Libexif project libexif integer overflow vulnerabilityA vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS)…EPSS 1.7%7.8CVE-2026-32775Libexif project libexif vulnerabilitylibexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer wou…EPSS 0.16%7.5CVE-2020-0198Google android integer overflow vulnerabilityIn exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of servic…EPSS 4.3%7.5CVE-2020-0181Google android integer overflow vulnerabilityIn exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial o…EPSS 2.9%7.5CVE-2020-13114Libexif project libexif allocation without limits vulnerabilityAn issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amoun…EPSS 2.3%7.5CVE-2018-20030Libexif project libexif uncontrolled resource consumption vulnerabilityAn error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU…EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2017-7544), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.