<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:17:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:3152 — Important: exiv2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:3152</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: exiv2-devel, AlmaLinux:8: exiv2-doc&lt;/p&gt;
&lt;p&gt;Exiv2 is a C++ library to access image metadata, supporting read and write access to the Exif, IPTC and XMP metadata, Exif MakerNote support, extract and delete methods for Exif thumbnails, classes to access Ifd, and support for various image formats.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp (CVE-2021-31291)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: exiv2-devel, AlmaLinux:8: exiv2-doc&lt;/p&gt;
&lt;p&gt;Exiv2 is a C++ library to access image metadata, supporting read and write access to the Exif, IPTC and XMP metadata, Exif MakerNote support, extract and delete methods for Exif thumbnails, classes to access Ifd, and support for various image formats.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp (CVE-2021-31291)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:3152</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-WK46975 — Rejected reason: DO NOT USE THIS CANDIDATE NUMBER</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-wk46975</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: exiv2&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the exiv2 package. Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: exiv2&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the exiv2 package. Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-wk46975</guid>
    </item>
    <item>
      <title>cnvd-2021-62190</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-62190</link>
      <description>cnvd-2021-62190</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-62190</guid>
    </item>
    <item>
      <title>fkie_cve-2021-31291</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-31291</link>
      <description>&lt;p&gt;Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29457. Reason: This candidate is a duplicate of CVE-2021-29457. Notes: All CVE users should reference CVE-2021-29457 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29457. Reason: This candidate is a duplicate of CVE-2021-29457. Notes: All CVE users should reference CVE-2021-29457 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-31291</guid>
    </item>
    <item>
      <title>GHSA-f74q-rm7p-mwq5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f74q-rm7p-mwq5</link>
      <description>&lt;p&gt;A heap-based buffer overflow vulnerability in jp2image.cpp of Exiv2 0.27.3 allows attackers to cause a denial of service (DOS) via crafted metadata.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-based buffer overflow vulnerability in jp2image.cpp of Exiv2 0.27.3 allows attackers to cause a denial of service (DOS) via crafted metadata.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f74q-rm7p-mwq5</guid>
    </item>
    <item>
      <title>gsd-2021-31291</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-31291</link>
      <description>gsd-2021-31291</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-31291</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12381-1 — exiv2-0.27.5-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12381-1</link>
      <description>&lt;p&gt;exiv2-0.27.5-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;exiv2-0.27.5-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12381-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3230 — Red Hat Security Advisory: compat-exiv2-026 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3230</link>
      <description>&lt;p&gt;exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3230</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3543-1 — Security update for exiv2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3543-1</link>
      <description>&lt;p&gt;Security update for exiv2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for exiv2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3543-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-31291</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-31291</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: exiv2, Ubuntu:18.04:LTS: exiv2, Ubuntu:20.04:LTS: exiv2&lt;/p&gt;
&lt;p&gt;Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29457. Reason: This candidate is a duplicate of CVE-2021-29457. Notes: All CVE users should reference CVE-2021-29457 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: exiv2, Ubuntu:18.04:LTS: exiv2, Ubuntu:20.04:LTS: exiv2&lt;/p&gt;
&lt;p&gt;Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29457. Reason: This candidate is a duplicate of CVE-2021-29457. Notes: All CVE users should reference CVE-2021-29457 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-31291</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1640 — Red Hat Enterprise Linux (exiv2): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Di…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1640</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux in der Komponente exiv2 ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux in der Komponente exiv2 ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1640</guid>
    </item>
  </channel>
</rss>
