Vulnerability index

Browse CVEs

148 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libtiff MEDIUM 6.5
CVE-2022-1210

A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a m…

No fix yet
Fix from $1,600 2022-04-03
Libtiff MEDIUM 5.5
CVE-2022-1056

Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile l…

Patch available
Fix from $1,600 2022-03-28
Libtiff MEDIUM 6.5
CVE-2014-8128

LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of serv…

Fix: 4.0.4+
Fix from $1,600 2020-02-12
Libtiff HIGH 8.8
CVE-2019-17546

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-ba…

Fix: 4.1.0+
Fix from $1,950 2019-10-14
Libtiff HIGH 7.5
CVE-2017-16232EPSS 5%

LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by t…

Patch available
Fix from $1,950 2019-03-21
Libtiff HIGH 8.8
CVE-2018-17795

The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflo…

No fix yet
Fix from $1,950 2018-09-30
Libtiff MEDIUM 6.5
CVE-2018-10801

TIFFClientOpen in tif_unix.c in LibTIFF 3.8.2 has memory leaks, as demonstrated by bmp2tiff.

No fix yet
Fix from $1,600 2018-05-08
Libtiff MEDIUM 6.5
CVE-2018-10126

ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16…

No fix yet
Fix from $1,600 2018-04-21
Libtiff HIGH 8.8
CVE-2018-5360

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/t…

Fix: 4.0.6+
Fix from $1,950 2018-01-14
Libtiff MEDIUM 6.5
CVE-2017-18013

In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.

Patch available
Fix from $1,600 2018-01-01
Libtiff HIGH 8.8
CVE-2017-17973

In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability …

No fix yet
Fix from $1,950 2017-12-29
Libtiff HIGH 8.8
CVE-2017-17942

In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c.

No fix yet
Fix from $1,950 2017-12-28
Libtiff HIGH 8.8
CVE-2017-17095EPSS 11%

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and appl…

No fix yet
Fix from $1,950 2017-12-02
Libtiff MEDIUM 6.5
CVE-2017-13726

There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted …

Mitigation only
Fix from $1,600 2017-08-29
Libtiff MEDIUM 6.5
CVE-2017-13727

There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A cr…

Mitigation only
Fix from $1,600 2017-08-29
Libtiff HIGH 7.5
CVE-2017-12944

The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to caus…

Mitigation only
Fix from $1,950 2017-08-18
Libtiff MEDIUM 6.5
CVE-2017-11613

In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a denial of service attack. Durin…

Mitigation only
Fix from $1,600 2017-07-26
Libtiff HIGH 8.8
CVE-2017-11335

There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred byte…

Mitigation only
Fix from $1,950 2017-07-17
Libtiff HIGH 7.5
CVE-2017-10688EPSS 7%

In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a…

No fix yet
Fix from $1,950 2017-06-29
Libtiff MEDIUM 6.5
CVE-2014-8127EPSS 6%

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesSt…

Mitigation only
Fix from $1,600 2017-06-26
Libtiff MEDIUM 6.5
CVE-2017-9937

In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of servic…

Fix: after 4.0.8
Fix from $1,600 2017-06-26
Libtiff MEDIUM 6.5
CVE-2017-9147EPSS 7%

LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash…

No fix yet
Fix from $1,600 2017-05-22
Libtiff MEDIUM 5.5
CVE-2016-10371

The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion …

Mitigation only
Fix from $1,600 2017-05-10
Libtiff HIGH 7.8
CVE-2017-7592

The putagreytile function in tif_getimage.c in LibTIFF 4.0.7 has a left-shift undefined behavior issue, which might allow remote attackers to cause a…

Mitigation only
Fix from $1,950 2017-04-09
Libtiff HIGH 7.8
CVE-2017-7596

LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause …

Patch available
Fix from $1,950 2017-04-09
Libtiff HIGH 7.8
CVE-2017-7597

tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote at…

Patch available
Fix from $1,950 2017-04-09
Libtiff HIGH 7.8
CVE-2017-7598

tif_dirread.c in LibTIFF 4.0.7 might allow remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted i…

Patch available
Fix from $1,950 2017-04-09
Libtiff HIGH 7.8
CVE-2017-7599

LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote attackers to cause …

Patch available
Fix from $1,950 2017-04-09
Libtiff HIGH 7.8
CVE-2017-7600

LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers t…

Patch available
Fix from $1,950 2017-04-09
Libtiff HIGH 7.8
CVE-2017-7601

LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of…

Patch available
Fix from $1,950 2017-04-09