Search

Found 66 results in 23ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-13727 medium 6.5 6.5 FIX slesdebian debian libtiff 9y ago There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of servic…
CVE-2017-13726 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 9y ago There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service atta…
CVE-2017-11613 medium 6.5 6.5 FIX arch arch slesdebian debian libtiff 9y ago In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a denial of service attack. During the TIFFOpen process, td_imagelength is not chec…
CVE-2014-8127 medium 6.5 6.5 FIX arch archsuse susedebian debian libtiff 9y ago LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, …
CVE-2017-9937 medium 6.5 6.5 slesdebian debian libtiff 9y ago In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.
CVE-2017-9936 medium 6.5 7.5 EXPFIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
CVE-2017-9815 medium 6.5 6.5 FIX slesubuntu ubuntudebian debian libtiff 9y ago In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function …
CVE-2017-9404 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9403 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9147 medium 6.5 7.5 EXPFIX slesdebian debian libtiff 9y ago LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
CVE-2017-9117 medium 4.0 4.0 FIX slesubuntu ubuntudebian debian libtiff 9y ago In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by …
CVE-2016-10371 medium 5.5 5.5 FIX slesdebian debian libtiff 9y ago The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF f…
CVE-2016-5322 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 9y ago The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
CVE-2017-7595 medium 5.5 5.5 FIX arch archdebian debian libtiff 9y ago The JPEGSetupEncode function in tiff_jpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.
CVE-2017-7594 medium 5.5 5.5 FIX arch arch slesdebian debian libtiff 9y ago The OJPEGReadHeaderInfoSecTablesDcTable function in tif_ojpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (memory leak) via a crafted image.
CVE-2017-7593 medium 5.5 5.5 FIX arch arch slesdebian debian libtiff 9y ago tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.
CVE-2016-10267 medium 5.5 5.5 FIX slesdebian debian libtiff 9y ago LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8.
CVE-2016-10266 medium 5.5 5.5 FIX slesdebian debian libtiff 9y ago LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_read.c:351:22.
CVE-2015-7313 medium 5.5 5.5 FIX arch archdebian debian libtiff 9y ago LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
CVE-2016-5315 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 9y ago The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
CVE-2016-10095 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 9y ago Stack-based buffer overflow in the _TIFFVGetField function in tif_dir.c in LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7…
CVE-2016-9532 medium 5.5 5.5 FIX arch arch slesdebian debian libtiff 9y ago Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.
CVE-2016-5102 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 9y ago Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.
CVE-2016-5321 medium 6.5 6.5 FIX slesarch archsuse suse libtiff 10y ago The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and crash) via a crafted tiff image.
CVE-2016-5319 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 10y ago Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file.
CVE-2016-5318 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 10y ago Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.
CVE-2016-5317 medium 6.5 6.5 FIX slesarch archsuse suse libtiff 10y ago Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME nautilus, allows attackers to cause a denial of service atta…
CVE-2016-5316 medium 6.5 6.5 FIX slesarch archsuse suse libtiff 10y ago Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr too…
CVE-2016-9273 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 10y ago tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.
CVE-2016-3625 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 10y ago tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.
CVE-2016-3622 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 10y ago The fpAcc function in tif_predict.c in the tiff2rgba tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted TIFF image.
CVE-2016-3619 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 10y ago The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote attackers to cause a denial of service (buffer over-r…
CVE-2016-3186 medium 6.2 6.2 FIX slesarch archsuse suse libtiff 10y ago Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.
CVE-2015-8784 medium 6.5 6.5 FIX slesdebian debian libtiff 10y ago The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image, as demonstrated by libtiff5.tif.
CVE-2015-8683 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 10y ago The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image.
CVE-2015-8665 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 10y ago tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via the SamplesPerPixel tag in a TIFF image.
CVE-2015-1547 medium 6.5 6.5 FIX debian debian libtiff 10y ago The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif.
CVE-2015-8783 medium 6.5 6.5 FIX debian debian libtiff 11y ago tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.
CVE-2015-8782 medium 6.5 6.5 FIX debian debian libtiff 11y ago tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CVE-2015-8781.
CVE-2015-8781 medium 6.5 6.5 FIX slesdebian debian libtiff 11y ago tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image, a different vulnerability than CVE…
CVE-2014-9330 medium 5.0 FIX debian debian libtiff 12y ago Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-boun…
CVE-2013-4231 medium 4.3 FIX debian debian libtiff 13y ago Multiple buffer overflows in libtiff before 4.0.3 allow remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) extension block in a GIF image or (2) GIF raster image to…
CVE-2013-4244 medium 6.8 FIX debian debian libtiff 13y ago The LZW decompressor in the gif2tiff tool in libtiff 4.0.3 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary co…
CVE-2013-4243 medium 6.8 FIX debian debian libtiff 13y ago Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c…
CVE-2013-4232 medium 6.8 FIX debian debian libtiff 13y ago Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary co…
CVE-2012-5581 medium 6.8 FIX debian debian libtiff 14y ago Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF …
CVE-2012-4564 medium 6.8 FIX ubuntu ubuntususe susedebian debian libtiff 14y ago ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM ima…
CVE-2012-4447 medium 6.8 FIX debian debian libtiff 14y ago Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF im…
CVE-2012-3401 medium 6.8 FIX debian debian libtiff 14y ago The t2p_read_tiff_init function in tiff2pdf (tools/tiff2pdf.c) in LibTIFF 4.0.2 and earlier does not properly initialize the T2P context struct pointer in certain error conditions, which allows conte…
CVE-2012-2113 medium 6.8 FIX debian debian libtiff 14y ago Multiple integer overflows in tiff2pdf in libtiff before 4.0.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tiff image, whi…
CVE-2012-1173 medium 6.8 FIX debian debian libtiff 14y ago Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTile…
CVE-2010-4665 medium 4.3 FIX debian debian libtiff 15y ago Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified …
CVE-2009-5022 medium 7.8 EXPFIX debian debian libtiff 15y ago Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.
CVE-2011-1167 medium 6.8 FIX debian debian libtiff 15y ago Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data…
CVE-2010-3087 medium 6.8 FIX suse susedebian debian libtiff 16y ago LibTIFF before 3.9.2-5.2.1 in SUSE openSUSE 11.3 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted TIFF image.
CVE-2010-2631 medium 5.3 EXPFIX debian debian libtiff 16y ago LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a den…
CVE-2010-2630 medium 5.3 EXPFIX debian debian libtiff 16y ago The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to ca…
CVE-2010-2483 medium 4.3 FIX debian debian libtiff 16y ago The TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a TIFF file with an invalid combination of SamplesPe…
CVE-2010-2482 medium 5.3 EXPFIX debian debian libtiff 16y ago LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via …
CVE-2010-2481 medium 4.3 FIX debian debian libtiff 16y ago The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly handle unknown tag types in TIFF directory entries, which allows remote attackers to cause a denial of service (out-of-bounds read …
CVE-2010-2597 medium 4.3 FIX debian debian libtiff 16y ago The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash…
CVE-2010-2596 medium 4.3 FIX arch archdebian debian libtiff 16y ago The OJPEGPostDecode function in tif_ojpeg.c in LibTIFF 3.9.0 and 3.9.2, as used in tiff2ps, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted…
CVE-2010-2595 medium 4.3 FIX debian debian libtiff 16y ago The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ImageMagick, does not properly handle invalid ReferenceBlackWhite values, which allows remote attackers to cause a denial of service…
CVE-2010-2443 medium 5.0 FIX debian debian libtiff 16y ago The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an OJPEG image with u…
CVE-2010-2067 medium 6.8 FIX ubuntu ubuntudebian debian libtiff 16y ago Stack-based buffer overflow in the TIFFFetchSubjectDistance function in tif_dirread.c in LibTIFF before 3.9.4 allows remote attackers to cause a denial of service (application crash) or possibly exec…
CVE-2010-2065 medium 6.8 FIX debian debian libtiff 16y ago Integer overflow in the TIFFroundup macro in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TIFF file t…