Search

Found 129 results in 38ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-4775 high 7.8 7.8 FIX rhel sles rocky libtiffredhat 1mo ago RHSA-2026:20585: compat-libtiff3 security update (Important)
CVE-2023-52356 high 7.5 7.5 FIX rhel rocky sles libtiff 7mo ago RHSA-2024:5079: libtiff security update (Moderate)
CVE-2025-8176 high 7.8 7.8 FIX rocky rhel sles libtiff 7mo ago RHSA-2025:20034: libtiff security update (Important)
CVE-2025-9165 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipul…
CVE-2025-8961 low 3.3 3.3 FIX slesdebian debian libtiff 10mo ago A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can …
CVE-2025-8534 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads …
CVE-2017-17095 high 8.8 9.8 EXPFIX rhel rocky sles libtiff 3y ago RHSA-2025:4658: libtiff security update (Moderate)
CVE-2017-17973 high 8.8 8.8 sles libtiff 9y ago In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue
CVE-2017-17942 high 8.8 8.8 FIX slesdebian debian libtiff 9y ago In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c.
CVE-2017-13727 medium 6.5 6.5 FIX slesdebian debian libtiff 9y ago There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of servic…
CVE-2017-13726 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 9y ago There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service atta…
CVE-2017-12944 high 7.5 7.5 FIX slesdebian debian libtiff 9y ago The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to cause a denial of service (allocation failure and appl…
CVE-2017-11613 medium 6.5 6.5 FIX arch arch slesdebian debian libtiff 9y ago In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a denial of service attack. During the TIFFOpen process, td_imagelength is not chec…
CVE-2017-11335 high 8.8 8.8 FIX slesdebian debian libtiff 9y ago There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred bytes out-of-bounds write (related to the ZIPDecode fu…
CVE-2017-10688 high 7.5 8.5 EXPFIX slesdebian debian libtiff 9y ago In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a remote denial of service attack.
CVE-2014-8127 medium 6.5 6.5 FIX arch archsuse susedebian debian libtiff 9y ago LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, …
CVE-2017-9937 medium 6.5 6.5 slesdebian debian libtiff 9y ago In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.
CVE-2017-9936 medium 6.5 7.5 EXPFIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
CVE-2017-9935 high 8.8 8.8 FIX arch arch slesdebian debian libtiff 9y ago In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can…
CVE-2017-9815 medium 6.5 6.5 FIX slesubuntu ubuntudebian debian libtiff 9y ago In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function …
CVE-2017-9404 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9403 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9147 medium 6.5 7.5 EXPFIX slesdebian debian libtiff 9y ago LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
CVE-2017-9117 medium 4.0 4.0 FIX slesubuntu ubuntudebian debian libtiff 9y ago In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by …
CVE-2016-10371 medium 5.5 5.5 FIX slesdebian debian libtiff 9y ago The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF f…
CVE-2016-5322 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 9y ago The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
CVE-2017-7602 high 7.8 7.8 FIX arch arch slesdebian debian libtiff 9y ago LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
CVE-2017-7601 high 7.8 7.8 FIX arch arch slesdebian debian libtiff 9y ago LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unsp…
CVE-2017-7600 high 7.8 7.8 FIX arch arch slesdebian debian libtiff 9y ago LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or…
CVE-2017-7599 high 7.8 7.8 FIX arch arch slesdebian debian libtiff 9y ago LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibl…
CVE-2017-7598 high 7.8 7.8 FIX arch arch slesdebian debian libtiff 9y ago tif_dirread.c in LibTIFF 4.0.7 might allow remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.
CVE-2017-7597 high 7.8 7.8 FIX arch arch slesdebian debian libtiff 9y ago tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application …
CVE-2017-7596 high 7.8 7.8 FIX arch arch slesdebian debian libtiff 9y ago LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibl…
CVE-2017-7595 medium 5.5 5.5 FIX arch archdebian debian libtiff 9y ago The JPEGSetupEncode function in tiff_jpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.
CVE-2017-7594 medium 5.5 5.5 FIX arch arch slesdebian debian libtiff 9y ago The OJPEGReadHeaderInfoSecTablesDcTable function in tif_ojpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (memory leak) via a crafted image.
CVE-2017-7593 medium 5.5 5.5 FIX arch arch slesdebian debian libtiff 9y ago tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.
CVE-2017-7592 high 7.8 7.8 FIX arch arch slesdebian debian libtiff 9y ago The putagreytile function in tif_getimage.c in LibTIFF 4.0.7 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly…
CVE-2016-10272 high 7.8 7.8 FIX slesdebian debian libtiff 9y ago LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to "WRITE of size 2048" and…
CVE-2016-10271 high 7.8 7.8 FIX slesdebian debian libtiff 9y ago tools/tiffcrop.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read and buffer overflow) or possibly have unspecified other impact via a crafted TIFF i…
CVE-2016-10270 high 7.8 7.8 FIX slesdebian debian libtiff 9y ago LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 8" and li…
CVE-2016-10269 high 7.8 7.8 FIX slesdebian debian libtiff 9y ago LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6 and 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer…
CVE-2016-10268 high 7.8 7.8 FIX slesdebian debian libtiff 9y ago tools/tiffcp.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (integer underflow and heap-based buffer under-read) or possibly have unspecified other impact via a crafted TIFF …
CVE-2016-10267 medium 5.5 5.5 FIX slesdebian debian libtiff 9y ago LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8.
CVE-2016-10266 medium 5.5 5.5 FIX slesdebian debian libtiff 9y ago LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_read.c:351:22.
CVE-2015-7313 medium 5.5 5.5 FIX arch archdebian debian libtiff 9y ago LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
CVE-2016-5315 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 9y ago The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
CVE-2016-10095 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 9y ago Stack-based buffer overflow in the _TIFFVGetField function in tif_dir.c in LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7…
CVE-2016-10094 high 7.8 7.8 FIX slesdebian debian libtiff 9y ago Off-by-one error in the t2p_readwrite_pdf_image_tile function in tools/tiff2pdf.c in LibTIFF 4.0.7 allows remote attackers to have unspecified impact via a crafted image.
CVE-2016-10093 high 7.8 7.8 FIX slesdebian debian libtiff 9y ago Integer overflow in tools/tiffcp.c in LibTIFF 4.0.7, 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5 and 4.0.…
CVE-2016-10092 high 7.8 7.8 FIX slesdebian debian libtiff 9y ago Heap-based buffer overflow in the readContigStripsIntoBuffer function in tif_unix.c in LibTIFF 4.0.7, 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.…
CVE-2016-9532 medium 5.5 5.5 FIX arch arch slesdebian debian libtiff 9y ago Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.
CVE-2016-5102 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 9y ago Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.
CVE-2016-9453 high 7.8 7.8 FIX slesarch archdebian debian libtiff 10y ago The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIF…
CVE-2016-9448 high 7.5 7.5 FIX arch arch slessuse suse libtiff 10y ago The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_…
CVE-2016-6223 critical 9.1 9.1 FIX slesarch archdebian debian libtiff 10y ago The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a …
CVE-2017-5563 high 8.8 8.8 FIX slesdebian debian libtiff 10y ago LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.
CVE-2016-5323 high 7.5 7.5 FIX slesarch archsuse suse libtiff 10y ago The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted Tiff image.
CVE-2016-5321 medium 6.5 6.5 FIX slesarch archsuse suse libtiff 10y ago The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and crash) via a crafted tiff image.
CVE-2016-5319 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 10y ago Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file.
CVE-2016-5318 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 10y ago Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.
CVE-2016-5317 medium 6.5 6.5 FIX slesarch archsuse suse libtiff 10y ago Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME nautilus, allows attackers to cause a denial of service atta…
CVE-2016-5316 medium 6.5 6.5 FIX slesarch archsuse suse libtiff 10y ago Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr too…
CVE-2016-9297 high 7.5 7.5 FIX arch arch slesdebian debian libtiff 10y ago The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values.
CVE-2016-9273 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 10y ago tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.
CVE-2017-5225 high 8.8 8.8 FIX slesdebian debian libtiff 10y ago LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.
CVE-2016-5652 high 7.0 7.0 FIX slesarch archdebian debian libtiff 10y ago An exploitable heap-based buffer overflow exists in the handling of TIFF images in LibTIFF's TIFF2PDF tool. A crafted TIFF document can lead to a heap-based buffer overflow resulting in remote code e…
CVE-2015-8870 high 7.4 7.4 FIX slesdebian debian libtiff 10y ago Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process …
CVE-2016-9540 critical 9.8 9.8 FIX arch arch slesdebian debian libtiff 10y ago tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width. Reported as MSVR 35103, aka "cpStripToTile heap-buffer-overflow."
CVE-2016-9539 critical 9.8 9.8 FIX arch arch slesdebian debian libtiff 10y ago tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.
CVE-2016-9538 critical 9.8 9.8 FIX arch arch slesdebian debian libtiff 10y ago tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 35100.
CVE-2016-9537 critical 9.8 9.8 FIX arch archdebian debian libtiff 10y ago tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.
CVE-2016-9536 critical 9.8 9.8 FIX arch arch slesdebian debian libtiff 10y ago tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip(). Reported as MSVR 35098, aka "t2p_process_jpeg_strip heap-buffer-overfl…
CVE-2016-9535 critical 9.8 9.8 FIX arch arch slesdebian debian libtiff 10y ago tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr…
CVE-2016-9534 critical 9.8 9.8 FIX arch arch slesdebian debian libtiff 10y ago tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members. Reported as MSVR 35095, aka "TIFFFlushData1 heap-buffer-ove…
CVE-2016-9533 critical 9.8 9.8 FIX arch arch slesdebian debian libtiff 10y ago tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers. Reported as MSVR 35094, aka "PixarLog horizontalDifference heap-buffer-overflow."
CVE-2016-8331 high 8.1 8.1 FIX slesdebian debian libtiff 10y ago An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remo…
CVE-2016-3658 high 7.5 7.5 FIX slesarch archdebian debian libtiff 10y ago The TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vecto…
CVE-2016-3634 high 7.5 7.5 FIX slesarch archdebian debian libtiff 10y ago The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag …
CVE-2016-3633 high 7.5 7.5 FIX slesarch archdebian debian libtiff 10y ago The setrow function in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the src variable.
CVE-2016-3631 high 7.5 7.5 FIX slesarch archdebian debian libtiff 10y ago The (1) cpStrips and (2) cpTiles functions in the thumbnail tool in LibTIFF 4.0.6 and earlier allow remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the bytec…
CVE-2016-3625 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 10y ago tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.
CVE-2016-3624 high 7.5 7.5 FIX slesarch archdebian debian libtiff 10y ago The cvtClump function in the rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) by setting the "-v" option to -1.
CVE-2016-3623 high 7.5 7.5 FIX slesarch archsuse suse libtiff 10y ago The rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero) by setting the (1) v or (2) h parameter to 0.
CVE-2016-3622 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 10y ago The fpAcc function in tif_predict.c in the tiff2rgba tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted TIFF image.
CVE-2016-3621 high 8.8 8.8 FIX slesarch archdebian debian libtiff 10y ago The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a …
CVE-2016-3620 high 7.5 7.5 FIX slesarch archdebian debian libtiff 10y ago The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a …
CVE-2016-3619 medium 6.5 6.5 FIX slesarch archdebian debian libtiff 10y ago The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote attackers to cause a denial of service (buffer over-r…
CVE-2016-3991 high 7.8 7.8 FIX slesarch archdebian debian libtiff 10y ago Heap-based buffer overflow in the loadImage function in the tiffcrop tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary …
CVE-2016-3990 high 7.8 7.8 FIX slesarch archdebian debian libtiff 10y ago Heap-based buffer overflow in the horizontalDifference8 function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code …
CVE-2016-3945 high 7.8 7.8 FIX slesarch archdebian debian libtiff 10y ago Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attackers to cause a denial …
CVE-2016-3632 high 7.8 7.8 FIX slesarch archdebian debian libtiff 10y ago The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image.
CVE-2016-3186 medium 6.2 6.2 FIX slesarch archsuse suse libtiff 10y ago Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.
CVE-2015-8784 medium 6.5 6.5 FIX slesdebian debian libtiff 10y ago The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image, as demonstrated by libtiff5.tif.
CVE-2015-8683 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 10y ago The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image.
CVE-2015-8665 medium 5.5 5.5 FIX slesarch archdebian debian libtiff 10y ago tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via the SamplesPerPixel tag in a TIFF image.
CVE-2015-1547 medium 6.5 6.5 FIX debian debian libtiff 10y ago The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif.
CVE-2015-8783 medium 6.5 6.5 FIX debian debian libtiff 11y ago tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.
CVE-2015-8782 medium 6.5 6.5 FIX debian debian libtiff 11y ago tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CVE-2015-8781.
CVE-2015-8781 medium 6.5 6.5 FIX slesdebian debian libtiff 11y ago tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image, a different vulnerability than CVE…
CVE-2015-8668 critical 9.8 9.8 FIX slesarch arch rhel libtifforacle 11y ago Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attackers to execute arbitrary code or cause a denial of service …