VYPR

Libtiff

by LibTIFF

Source repositories

CVEs (272)

  • CVE-2022-34266MedJul 19, 2022
    risk 0.36cvss 5.5epss 0.00

    The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range may be passed as an argument to the…

  • CVE-2022-2058MedJun 30, 2022
    risk 0.36cvss 5.5epss 0.01

    Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.

  • CVE-2022-2057MedJun 30, 2022
    risk 0.36cvss 5.5epss 0.01

    Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.

  • CVE-2022-2056MedJun 30, 2022
    risk 0.36cvss 5.5epss 0.01

    Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.

  • CVE-2022-1056MedMar 28, 2022
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.

  • CVE-2022-0924MedMar 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.

  • CVE-2022-0909MedMar 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa.

  • CVE-2022-0907MedMar 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.

  • CVE-2022-0865MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.01

    Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.

  • CVE-2022-22844MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.

  • CVE-2020-35522MedMar 9, 2021
    risk 0.36cvss 5.5epss 0.02

    In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack.

  • CVE-2020-35521MedMar 9, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service.

  • CVE-2019-7663MedFeb 9, 2019
    risk 0.36cvss 6.5epss 0.03

    An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a…

  • CVE-2014-8130MedMar 12, 2018
    risk 0.36cvss 6.5epss 0.04

    The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in…

  • CVE-2016-10371MedMay 10, 2017
    risk 0.36cvss 5.5epss 0.01

    The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file.

  • CVE-2016-5322MedApr 11, 2017
    risk 0.36cvss 5.5epss 0.02

    The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.

  • CVE-2017-7595MedApr 9, 2017
    risk 0.36cvss 5.5epss 0.01

    The JPEGSetupEncode function in tiff_jpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.

  • CVE-2017-7594MedApr 9, 2017
    risk 0.36cvss 5.5epss 0.02

    The OJPEGReadHeaderInfoSecTablesDcTable function in tif_ojpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (memory leak) via a crafted image.

  • CVE-2017-7593MedApr 9, 2017
    risk 0.36cvss 5.5epss 0.02

    tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.

  • CVE-2015-7313MedMar 17, 2017
    risk 0.36cvss 5.5epss 0.02

    LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.

Page 8 of 14