CVE-2009-2687

4.3
CVSS v2.0 Base Score
4.38%
LOW RiskEPSS (91st percentile)

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

Published: 8/5/2009
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

4.3

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Score (Exploitation Probability)

4.38%LOW Exploitation Risk
91st percentile

This vulnerability has a 4.38% probability of being exploited in the next 30 days, ranking higher than 91% of all scored CVEs.

CWE Classification

Advertisement