CVE-2019-14982: EXIV2

Medium severity, CVSS 6.5. EPSS: 2% chance of exploitation in the next 30 days.

In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.

Affected products

  • EXIV2 EXIV2: before 0.27.2 (fixed in 0.27.2)

Published 2019-08-12. Last modified 2026-06-17.