VendorsSentexjhead1.9
Vulnerabilities

Sentex Jhead 1.9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2008-4641
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.
Published 2008-10-21 · Modified
10.0EPSS 0.022
CVE-2008-4575
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
Published 2008-10-15 · Modified
5.0EPSS 0.017
CVE-2008-4639
jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
Published 2008-10-21 · Modified
4.6EPSS 0.003
CVE-2008-4640
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.
Published 2008-10-21 · Modified
3.6EPSS 0.003