Marcus Meissner
19 exploits
Active since Jun 2002
QEMU < 2.3.0 - Memory Corruption via Floppy Disk Controller Commands
exif < 0.6.22 - Denial of Service via Malicious JPEG File
CVSS 5.5
libgphoto2 has OOB read in ptp_unpack_EOS_ImageFormat() and ptp_unpack_EOS_CustomFuncEx() due to missing length parameter in ptp-pack.c
CVSS 6.1
libgphoto2 missing null termination in ptp_unpack_Canon_FE() filename buffer in ptp-pack.c
CVSS 3.5
libgphoto2 has OOB read in ptp_unpack_DPV() UINT128/INT128 handling in ptp-pack.c
CVSS 5.2
libgphoto2 has memory leak in ptp_unpack_Sony_DPD() secondary enumeration list in ptp-pack.c
CVSS 2.4
libgphoto2 has OOB read in ptp_unpack_Sony_DPD() enumeration count parsing in ptp-pack.c
CVSS 5.2
libgphoto2 has OOB read in ptp_unpack_Sony_DPD() FormFlag parsing in ptp-pack.c
CVSS 5.2
libgphoto2 has OOB read in ptp_unpack_OI() in ptp-pack.c via malicious PTP ObjectInfo response
CVSS 6.1
libgphoto2 <=2.5.33 ptp_unpack_EOS_FocusInfoEx - Out-of-Bounds Read
CVSS 3.5
libexif < 0.6.25 - Integer Overflow in Nikon MakerNote Handling
CVSS 4.0
libexif < 0.6.25 - Integer Underflow in Fuji and Olympus MakerNote Decoding
CVSS 4.0
libexif through 0.6.25 - Memory Corruption
CVSS 7.4
Android 10 - Integer Overflow in libexif
CVSS 8.8
libexif < 0.6.22 - Out-of-bounds Read in EXIF MakerNote Handling
CVSS 9.1
exif < 0.6.22 - Denial of Service via Malicious JPEG File
CVSS 5.5
QEMU < 2.3.0 - Memory Corruption via Floppy Disk Controller Commands
XChat <= 1.8.7 - Remote IRC Command Execution via CTCP PING Response
Linux kernel < 4.10.13 - Denial of Service via KEY_REQKEY_DEFL_THREAD_KEYRING Keyctl Calls
CVSS 5.5