CVE-2017-7544: Libexif Project Libexif

Critical severity, CVSS 9.1. EPSS: 3.3% chance of exploitation in the next 30 days.

libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.

Affected products

Published 2017-09-21. Last modified 2026-06-17.