VYPR

Libtiff

by LibTIFF

Source repositories

CVEs (272)

  • CVE-2018-19210MedNov 12, 2018
    risk 0.43cvss 6.5epss 0.04

    In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

  • CVE-2018-17000MedSep 13, 2018
    risk 0.43cvss 6.5epss 0.03

    A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This vulnerability can be triggered by the executable tiffcp.

  • CVE-2018-10963MedMay 10, 2018
    risk 0.43cvss 6.5epss 0.04

    The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726.

  • CVE-2014-8127MedJun 26, 2017
    risk 0.43cvss 6.5epss 0.06

    LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3)…

  • CVE-2016-5319MedJan 20, 2017
    risk 0.43cvss 6.5epss 0.04

    Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file.

  • CVE-2016-5318MedJan 20, 2017
    risk 0.43cvss 6.5epss 0.05

    Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.

  • CVE-2016-3622MedOct 3, 2016
    risk 0.43cvss 6.5epss 0.04

    The fpAcc function in tif_predict.c in the tiff2rgba tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted TIFF image.

  • CVE-2015-1547MedApr 13, 2016
    risk 0.43cvss 6.5epss 0.03

    The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif.

  • CVE-2023-52355HigJan 25, 2024
    risk 0.42cvss 7.5epss 0.02

    An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

  • CVE-2023-6277MedNov 24, 2023
    risk 0.42cvss 6.5epss 0.02

    An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

  • CVE-2023-41175MedOct 5, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

  • CVE-2023-40745MedOct 5, 2023
    risk 0.42cvss 6.5epss 0.01

    LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

  • CVE-2022-40090MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file.

  • CVE-2023-3618MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.

  • CVE-2022-2521MedAug 31, 2022
    risk 0.42cvss 6.5epss 0.01

    It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can cause a program crash and denial of service while processing crafted input.

  • CVE-2022-2520MedAug 31, 2022
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input.

  • CVE-2022-2519MedAug 31, 2022
    risk 0.42cvss 6.5epss 0.01

    There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1

  • CVE-2022-34526MedJul 29, 2022
    risk 0.42cvss 6.5epss 0.02

    A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.

  • CVE-2020-19144MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.

  • CVE-2020-19143MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'.

Page 5 of 14