CVEs (262)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian LibtiffNetapp3Debian Linux LibtiffOntap Select Deploy Administration UtilityNov 21, 2024 Jan 10, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field. |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreNov 21, 2024 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerabi...Show more |
4Debian LibtiffNetapp+1 more4Debian Linux Enterprise LinuxLibtiff+1 moreNov 21, 2024 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this...Show more |
4Fedoraproject LibtiffNetapp+1 more4Enterprise Linux FedoraLibtiff+1 moreNov 21, 2024 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack. |
4Fedoraproject LibtiffNetapp+1 more4Enterprise Linux FedoraLibtiff+1 moreNov 21, 2024 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service. |
LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image. |
tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-si...Show more |
4Debian FedoraprojectLibtiff+1 more4Debian Linux FedoraLeap+1 moreNov 21, 2024 Aug 14, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 _TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for exampl...Show more |
3Libtiff OpensuseSuse5Leap LibtiffLinux Enterprise Desktop+2 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to...Show more |
4Canonical DebianLibtiff+1 more4Debian Linux LeapLibtiff+1 moreNov 21, 2024 Feb 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leve...Show more |
4Canonical DebianLibtiff+1 more4Debian Linux LeapLibtiff+1 moreNov 21, 2024 Jan 11, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxNov 21, 2024 Nov 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset. |
2Canonical Libtiff2Libtiff Ubuntu LinuxNov 21, 2024 Oct 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxNov 21, 2024 Oct 22, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-siz...Show more |
The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via...Show more |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxNov 21, 2024 Sep 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other im...Show more |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxNov 21, 2024 Sep 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxNov 21, 2024 Sep 13, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This...Show more |
2Debian Libtiff2Debian Linux LibtiffNov 21, 2024 Sep 2, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified...Show more |
2Debian Libtiff2Debian Linux LibtiffNov 21, 2024 Aug 8, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a craf...Show more |