CVE-2021-3496: Jhead Project Jhead

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.

Affected products

Published 2021-04-22. Last modified 2026-06-17.