Skip to content
Noroxi

libtiff records

262 published records for vendor libtiff.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 0.4%
Pre-auth RCE
37
With a fix record
98.9%
Median publish → KEV
No record has entered KEV

All records

262 records
  • Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow co

    HighCVSS 7.5WeaponizedEPSS 54%

    libtiff · libtiffAug 2, 2006

  • Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a

    CriticalCVSS 10.0No exploitEPSS 15%

    libtiff · libtiffJan 10, 2005

  • Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.

    HighCVSS 8.8No exploitEPSS 25%

    libtiff · libtiffJun 26, 2018

  • Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attack

    CriticalCVSS 9.8No exploitEPSS 14%

    libtiff · libtiffJan 8, 2016

  • Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT

    CriticalCVSS 10.0No exploitEPSS 8%

    libtiff · libtiffJan 27, 2005

  • tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in r

    CriticalCVSS 9.8No exploitEPSS 5%

    libtiff · libtiffNov 22, 2016

  • The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or

    CriticalCVSS 9.8No exploitEPSS 4%

    libtiff · libtiffJan 8, 2016

  • tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width.

    CriticalCVSS 9.8No exploitEPSS 4%

    libtiff · libtiffNov 22, 2016

  • tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members.

    CriticalCVSS 9.8No exploitEPSS 4%

    libtiff · libtiffNov 22, 2016

  • tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow.

    CriticalCVSS 9.8No exploitEPSS 3%

    libtiff · libtiffNov 22, 2016

  • tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers.

    CriticalCVSS 9.8No exploitEPSS 3%

    libtiff · libtiffNov 22, 2016

  • tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers.

    CriticalCVSS 9.8No exploitEPSS 3%

    libtiff · libtiffNov 22, 2016

  • tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip().

    CriticalCVSS 9.8No exploitEPSS 3%

    libtiff · libtiffNov 22, 2016

  • tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer().

    CriticalCVSS 9.8No exploitEPSS 3%

    libtiff · libtiffNov 22, 2016

  • LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta,

    HighCVSS 8.8Proof of conceptEPSS 15%

    libtiff · libtiffOct 22, 2018

  • tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow

    HighCVSS 8.8Proof of conceptEPSS 11%

    libtiff · libtiffDec 2, 2017

  • CVE-2009-2347
    38Monitor

    Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attacke

    CriticalCVSS 9.3No exploitEPSS 4%

    libtiff · libtiffJul 14, 2009

  • CVE-2016-6223
    37Monitor

    The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of serv

    CriticalCVSS 9.1No exploitEPSS 3%

    libtiff · libtiffJan 23, 2017

  • CVE-2016-5314
    36Monitor

    Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of s

    HighCVSS 8.8No exploitEPSS 4%

    libtiff · libtiffMar 11, 2018

  • CVE-2017-5225
    36Monitor

    LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSa

    HighCVSS 8.8No exploitEPSS 4%

    libtiff · libtiffJan 12, 2017

  • The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffe

    HighCVSS 8.8No exploitEPSS 4%

    libtiff · libtiffSep 30, 2018

  • ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer over

    HighCVSS 8.8No exploitEPSS 4%

    libtiff · libtiffAug 8, 2018

  • CVE-2017-9935
    36Monitor

    In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c.

    HighCVSS 8.8No exploitEPSS 4%

    libtiff · libtiffJun 26, 2017

  • CVE-2019-6128
    36Monitor

    The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.

    HighCVSS 8.8No exploitEPSS 4%

    libtiff · libtiffJan 11, 2019

  • CVE-2014-8129
    36Monitor

    LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a cra

    HighCVSS 8.8No exploitEPSS 4%

    libtiff · libtiffMar 11, 2018