Записи libtiff
262 опубликованных записей вендора libtiff.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,4 %
- Pre-auth RCE
- 37
- С записью об исправлении
- 98,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer57
- CWE-125 Out-of-bounds Read39
- CWE-787 Out-of-bounds Write37
- CWE-20 Improper Input Validation18
- CWE-476 NULL Pointer Dereference15
- CWE-369 Divide By Zero13
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
262 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2006-3459Готовый эксплойт | Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow colibtiff · libtiff · CWE-119 | Высокая7,5 | — | 53,7 % | 2 авг. 2006 г. |
44В плане | CVE-2004-1308Эксплойта нет | Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via alibtiff · libtiff | Критическая10,0 | — | 15,0 % | 10 янв. 2005 г. |
43В плане | CVE-2018-12900Эксплойта нет | Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.libtiff · libtiff · CWE-787 | Высокая8,8 | — | 25,2 % | 26 июн. 2018 г. |
43В плане | CVE-2015-8668Эксплойта нет | Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attacklibtiff · libtiff · CWE-787 | Критическая9,8 | — | 13,7 % | 8 янв. 2016 г. |
42В плане | CVE-2004-0929Эксплойта нет | Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORTlibtiff · libtiff | Критическая10,0 | — | 8,2 % | 27 янв. 2005 г. |
40В плане | CVE-2016-9535Эксплойта нет | tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in rlibtiff · libtiff · CWE-119 | Критическая9,8 | — | 4,8 % | 22 нояб. 2016 г. |
40В плане | CVE-2015-7554Эксплойта нет | The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or libtiff · libtiff · CWE-254 | Критическая9,8 | — | 4,2 % | 8 янв. 2016 г. |
40В плане | CVE-2016-9540Эксплойта нет | tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width.libtiff · libtiff · CWE-119 | Критическая9,8 | — | 3,6 % | 22 нояб. 2016 г. |
40В плане | CVE-2016-9534Эксплойта нет | tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members.libtiff · libtiff · CWE-119 | Критическая9,8 | — | 3,6 % | 22 нояб. 2016 г. |
40В плане | CVE-2016-9538Эксплойта нет | tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow.libtiff · libtiff · CWE-190 | Критическая9,8 | — | 3,4 % | 22 нояб. 2016 г. |
40В плане | CVE-2016-9533Эксплойта нет | tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers.libtiff · libtiff · CWE-119 | Критическая9,8 | — | 3,2 % | 22 нояб. 2016 г. |
40В плане | CVE-2016-9537Эксплойта нет | tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers.libtiff · libtiff · CWE-119 | Критическая9,8 | — | 3,1 % | 22 нояб. 2016 г. |
40В плане | CVE-2016-9536Эксплойта нет | tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip().libtiff · libtiff · CWE-119 | Критическая9,8 | — | 3,1 % | 22 нояб. 2016 г. |
40В плане | CVE-2016-9539Эксплойта нет | tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer().libtiff · libtiff · CWE-119 | Критическая9,8 | — | 3,0 % | 22 нояб. 2016 г. |
39Наблюдать | CVE-2018-18557Proof of concept | LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, libtiff · libtiff · CWE-787 | Высокая8,8 | — | 15,0 % | 22 окт. 2018 г. |
38Наблюдать | CVE-2017-17095Proof of concept | tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflowlibtiff · libtiff · CWE-119 | Высокая8,8 | — | 10,6 % | 2 дек. 2017 г. |
38Наблюдать | CVE-2009-2347Эксплойта нет | Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackelibtiff · libtiff · CWE-189 | Критическая9,3 | — | 4,2 % | 14 июл. 2009 г. |
37Наблюдать | CVE-2016-6223Эксплойта нет | The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of servlibtiff · libtiff · CWE-189 | Критическая9,1 | — | 3,3 % | 23 янв. 2017 г. |
36Наблюдать | CVE-2016-5314Эксплойта нет | Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of slibtiff · libtiff · CWE-787 | Высокая8,8 | — | 4,4 % | 11 мар. 2018 г. |
36Наблюдать | CVE-2017-5225Эксплойта нет | LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSalibtiff · libtiff · CWE-119 | Высокая8,8 | — | 4,4 % | 12 янв. 2017 г. |
36Наблюдать | CVE-2018-17795Эксплойта нет | The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffelibtiff · libtiff · CWE-787 | Высокая8,8 | — | 4,1 % | 30 сент. 2018 г. |
36Наблюдать | CVE-2018-15209Эксплойта нет | ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overlibtiff · libtiff · CWE-787 | Высокая8,8 | — | 4,0 % | 8 авг. 2018 г. |
36Наблюдать | CVE-2017-9935Эксплойта нет | In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c.libtiff · libtiff · CWE-125 | Высокая8,8 | — | 3,9 % | 26 июн. 2017 г. |
36Наблюдать | CVE-2019-6128Эксплойта нет | The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.libtiff · libtiff · CWE-401 | Высокая8,8 | — | 3,9 % | 11 янв. 2019 г. |
36Наблюдать | CVE-2014-8129Эксплойта нет | LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a cralibtiff · libtiff · CWE-787 | Высокая8,8 | — | 3,7 % | 11 мар. 2018 г. |
- CVE-2006-345946В плане
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow co
ВысокаяCVSS 7,5Готовый эксплойтEPSS 54 %libtiff · libtiff2 авг. 2006 г.
- CVE-2004-130844В плане
Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a
КритическаяCVSS 10,0Эксплойта нетEPSS 15 %libtiff · libtiff10 янв. 2005 г.
- CVE-2018-1290043В плане
Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.
ВысокаяCVSS 8,8Эксплойта нетEPSS 25 %libtiff · libtiff26 июн. 2018 г.
- CVE-2015-866843В плане
Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attack
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %libtiff · libtiff8 янв. 2016 г.
- CVE-2004-092942В плане
Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %libtiff · libtiff27 янв. 2005 г.
- CVE-2016-953540В плане
tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in r
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %libtiff · libtiff22 нояб. 2016 г.
- CVE-2015-755440В плане
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %libtiff · libtiff8 янв. 2016 г.
- CVE-2016-954040В плане
tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %libtiff · libtiff22 нояб. 2016 г.
- CVE-2016-953440В плане
tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %libtiff · libtiff22 нояб. 2016 г.
- CVE-2016-953840В плане
tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libtiff · libtiff22 нояб. 2016 г.
- CVE-2016-953340В плане
tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libtiff · libtiff22 нояб. 2016 г.
- CVE-2016-953740В плане
tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libtiff · libtiff22 нояб. 2016 г.
- CVE-2016-953640В плане
tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip().
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libtiff · libtiff22 нояб. 2016 г.
- CVE-2016-953940В плане
tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer().
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libtiff · libtiff22 нояб. 2016 г.
- CVE-2018-1855739Наблюдать
LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta,
ВысокаяCVSS 8,8Proof of conceptEPSS 15 %libtiff · libtiff22 окт. 2018 г.
- CVE-2017-1709538Наблюдать
tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow
ВысокаяCVSS 8,8Proof of conceptEPSS 11 %libtiff · libtiff2 дек. 2017 г.
- CVE-2009-234738Наблюдать
Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attacke
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %libtiff · libtiff14 июл. 2009 г.
- CVE-2016-622337Наблюдать
The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of serv
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %libtiff · libtiff23 янв. 2017 г.
- CVE-2016-531436Наблюдать
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of s
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %libtiff · libtiff11 мар. 2018 г.
- CVE-2017-522536Наблюдать
LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSa
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %libtiff · libtiff12 янв. 2017 г.
- CVE-2018-1779536Наблюдать
The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffe
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %libtiff · libtiff30 сент. 2018 г.
- CVE-2018-1520936Наблюдать
ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer over
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %libtiff · libtiff8 авг. 2018 г.
- CVE-2017-993536Наблюдать
In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %libtiff · libtiff26 июн. 2017 г.
- CVE-2019-612836Наблюдать
The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %libtiff · libtiff11 янв. 2019 г.
- CVE-2014-812936Наблюдать
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a cra
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %libtiff · libtiff11 мар. 2018 г.