VendorsGooglepicasaany version
Vulnerabilities

Google Picasa any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2015-8221
Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, which triggers a heap-based buffer overflow.
Published 2015-11-17 · Modified
10.0EPSS 0.040
CVE-2011-2747
Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file.
Published 2011-07-28 · Modified
9.3EPSS 0.043
CVE-2007-4823
Multiple buffer overflows in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.
Published 2007-09-11 · Modified
7.5EPSS 0.005
CVE-2011-0458
Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.
Published 2011-03-28 · Modified
6.9EPSS 0.003
CVE-2007-4824
Multiple cross-application scripting (XAS) vulnerabilities in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.
Published 2007-09-11 · Modified
6.8EPSS 0.004
CVE-2007-4847
Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa:// URI. NOTE: this information is based upon a vague pre-advisory.
Published 2007-09-12 · Modified
5.0EPSS 0.005