libtiff kayıtları
libtiff üreticisine ait 262 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,4
- Pre-auth RCE
- 37
- Düzeltme kaydı olan
- %98,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer57
- CWE-125 Out-of-bounds Read39
- CWE-787 Out-of-bounds Write37
- CWE-20 Improper Input Validation18
- CWE-476 NULL Pointer Dereference15
- CWE-369 Divide By Zero13
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
262 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2006-3459Silahlaştırılmış | Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow colibtiff · libtiff · CWE-119 | Yüksek7,5 | — | %53,7 | 2 Ağu 2006 |
44Planlayın | CVE-2004-1308İstismar yok | Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via alibtiff · libtiff | Kritik10,0 | — | %15,0 | 10 Oca 2005 |
43Planlayın | CVE-2018-12900İstismar yok | Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.libtiff · libtiff · CWE-787 | Yüksek8,8 | — | %25,2 | 26 Haz 2018 |
43Planlayın | CVE-2015-8668İstismar yok | Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attacklibtiff · libtiff · CWE-787 | Kritik9,8 | — | %13,7 | 8 Oca 2016 |
42Planlayın | CVE-2004-0929İstismar yok | Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORTlibtiff · libtiff | Kritik10,0 | — | %8,2 | 27 Oca 2005 |
40Planlayın | CVE-2016-9535İstismar yok | tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in rlibtiff · libtiff · CWE-119 | Kritik9,8 | — | %4,8 | 22 Kas 2016 |
40Planlayın | CVE-2015-7554İstismar yok | The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or libtiff · libtiff · CWE-254 | Kritik9,8 | — | %4,2 | 8 Oca 2016 |
40Planlayın | CVE-2016-9540İstismar yok | tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width.libtiff · libtiff · CWE-119 | Kritik9,8 | — | %3,6 | 22 Kas 2016 |
40Planlayın | CVE-2016-9534İstismar yok | tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members.libtiff · libtiff · CWE-119 | Kritik9,8 | — | %3,6 | 22 Kas 2016 |
40Planlayın | CVE-2016-9538İstismar yok | tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow.libtiff · libtiff · CWE-190 | Kritik9,8 | — | %3,4 | 22 Kas 2016 |
40Planlayın | CVE-2016-9533İstismar yok | tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers.libtiff · libtiff · CWE-119 | Kritik9,8 | — | %3,2 | 22 Kas 2016 |
40Planlayın | CVE-2016-9537İstismar yok | tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers.libtiff · libtiff · CWE-119 | Kritik9,8 | — | %3,1 | 22 Kas 2016 |
40Planlayın | CVE-2016-9536İstismar yok | tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip().libtiff · libtiff · CWE-119 | Kritik9,8 | — | %3,1 | 22 Kas 2016 |
40Planlayın | CVE-2016-9539İstismar yok | tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer().libtiff · libtiff · CWE-119 | Kritik9,8 | — | %3,0 | 22 Kas 2016 |
39İzleyin | CVE-2018-18557Kavram kanıtı | LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, libtiff · libtiff · CWE-787 | Yüksek8,8 | — | %15,0 | 22 Eki 2018 |
38İzleyin | CVE-2017-17095Kavram kanıtı | tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflowlibtiff · libtiff · CWE-119 | Yüksek8,8 | — | %10,6 | 2 Ara 2017 |
38İzleyin | CVE-2009-2347İstismar yok | Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackelibtiff · libtiff · CWE-189 | Kritik9,3 | — | %4,2 | 14 Tem 2009 |
37İzleyin | CVE-2016-6223İstismar yok | The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of servlibtiff · libtiff · CWE-189 | Kritik9,1 | — | %3,3 | 23 Oca 2017 |
36İzleyin | CVE-2016-5314İstismar yok | Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of slibtiff · libtiff · CWE-787 | Yüksek8,8 | — | %4,4 | 11 Mar 2018 |
36İzleyin | CVE-2017-5225İstismar yok | LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSalibtiff · libtiff · CWE-119 | Yüksek8,8 | — | %4,4 | 12 Oca 2017 |
36İzleyin | CVE-2018-17795İstismar yok | The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffelibtiff · libtiff · CWE-787 | Yüksek8,8 | — | %4,1 | 30 Eyl 2018 |
36İzleyin | CVE-2018-15209İstismar yok | ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overlibtiff · libtiff · CWE-787 | Yüksek8,8 | — | %4,0 | 8 Ağu 2018 |
36İzleyin | CVE-2017-9935İstismar yok | In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c.libtiff · libtiff · CWE-125 | Yüksek8,8 | — | %3,9 | 26 Haz 2017 |
36İzleyin | CVE-2019-6128İstismar yok | The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.libtiff · libtiff · CWE-401 | Yüksek8,8 | — | %3,9 | 11 Oca 2019 |
36İzleyin | CVE-2014-8129İstismar yok | LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a cralibtiff · libtiff · CWE-787 | Yüksek8,8 | — | %3,7 | 11 Mar 2018 |
- CVE-2006-345946Planlayın
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow co
YüksekCVSS 7,5SilahlaştırılmışEPSS %54libtiff · libtiff2 Ağu 2006
- CVE-2004-130844Planlayın
Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a
KritikCVSS 10,0İstismar yokEPSS %15libtiff · libtiff10 Oca 2005
- CVE-2018-1290043Planlayın
Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.
YüksekCVSS 8,8İstismar yokEPSS %25libtiff · libtiff26 Haz 2018
- CVE-2015-866843Planlayın
Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attack
KritikCVSS 9,8İstismar yokEPSS %14libtiff · libtiff8 Oca 2016
- CVE-2004-092942Planlayın
Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT
KritikCVSS 10,0İstismar yokEPSS %8libtiff · libtiff27 Oca 2005
- CVE-2016-953540Planlayın
tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in r
KritikCVSS 9,8İstismar yokEPSS %5libtiff · libtiff22 Kas 2016
- CVE-2015-755440Planlayın
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or
KritikCVSS 9,8İstismar yokEPSS %4libtiff · libtiff8 Oca 2016
- CVE-2016-954040Planlayın
tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width.
KritikCVSS 9,8İstismar yokEPSS %4libtiff · libtiff22 Kas 2016
- CVE-2016-953440Planlayın
tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members.
KritikCVSS 9,8İstismar yokEPSS %4libtiff · libtiff22 Kas 2016
- CVE-2016-953840Planlayın
tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow.
KritikCVSS 9,8İstismar yokEPSS %3libtiff · libtiff22 Kas 2016
- CVE-2016-953340Planlayın
tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers.
KritikCVSS 9,8İstismar yokEPSS %3libtiff · libtiff22 Kas 2016
- CVE-2016-953740Planlayın
tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers.
KritikCVSS 9,8İstismar yokEPSS %3libtiff · libtiff22 Kas 2016
- CVE-2016-953640Planlayın
tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip().
KritikCVSS 9,8İstismar yokEPSS %3libtiff · libtiff22 Kas 2016
- CVE-2016-953940Planlayın
tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer().
KritikCVSS 9,8İstismar yokEPSS %3libtiff · libtiff22 Kas 2016
- CVE-2018-1855739İzleyin
LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta,
YüksekCVSS 8,8Kavram kanıtıEPSS %15libtiff · libtiff22 Eki 2018
- CVE-2017-1709538İzleyin
tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow
YüksekCVSS 8,8Kavram kanıtıEPSS %11libtiff · libtiff2 Ara 2017
- CVE-2009-234738İzleyin
Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attacke
KritikCVSS 9,3İstismar yokEPSS %4libtiff · libtiff14 Tem 2009
- CVE-2016-622337İzleyin
The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of serv
KritikCVSS 9,1İstismar yokEPSS %3libtiff · libtiff23 Oca 2017
- CVE-2016-531436İzleyin
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of s
YüksekCVSS 8,8İstismar yokEPSS %4libtiff · libtiff11 Mar 2018
- CVE-2017-522536İzleyin
LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSa
YüksekCVSS 8,8İstismar yokEPSS %4libtiff · libtiff12 Oca 2017
- CVE-2018-1779536İzleyin
The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffe
YüksekCVSS 8,8İstismar yokEPSS %4libtiff · libtiff30 Eyl 2018
- CVE-2018-1520936İzleyin
ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer over
YüksekCVSS 8,8İstismar yokEPSS %4libtiff · libtiff8 Ağu 2018
- CVE-2017-993536İzleyin
In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c.
YüksekCVSS 8,8İstismar yokEPSS %4libtiff · libtiff26 Haz 2017
- CVE-2019-612836İzleyin
The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.
YüksekCVSS 8,8İstismar yokEPSS %4libtiff · libtiff11 Oca 2019
- CVE-2014-812936İzleyin
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a cra
YüksekCVSS 8,8İstismar yokEPSS %4libtiff · libtiff11 Mar 2018