Vulnerability index

Browse CVEs

148 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libtiff HIGH 7.5
CVE-2012-2088EPSS 6%

Integer signedness error in the TIFFReadDirectory function in tif_dirread.c in libtiff 3.9.4 and earlier allows remote attackers to cause a denial of…

Fix: after 3.9.4
Fix from $1,950 2012-07-22
Libtiff MEDIUM 6.8
CVE-2012-2113EPSS 6%

Multiple integer overflows in tiff2pdf in libtiff before 4.0.2 allow remote attackers to cause a denial of service (application crash) or possibly ex…

Fix: after 4.0.1
Fix from $1,600 2012-07-22
Libtiff MEDIUM 6.8
CVE-2012-1173EPSS 7%

Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF fil…

Mitigation only
Fix from $1,600 2012-06-04
Libtiff MEDIUM 6.8
CVE-2009-5022EPSS 11%

Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafte…

Fix: after 3.9.4
Fix from $1,600 2011-05-03
Libtiff MEDIUM 6.8
CVE-2011-1167EPSS 6%

Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute …

Fix: after 3.9.4
Fix from $1,600 2011-03-28
Libtiff MEDIUM 6.8
CVE-2010-3087

LibTIFF before 3.9.2-5.2.1 in SUSE openSUSE 11.3 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitra…

Mitigation only
Fix from $1,600 2010-09-28
Libtiff HIGH 7.5
CVE-2010-2233

tif_getimage.c in LibTIFF 3.9.0 and 3.9.2 on 64-bit platforms, as used in ImageMagick, does not properly perform vertical flips, which allows remote …

Patch available
Fix from $1,950 2010-07-02
Libtiff MEDIUM 5.0
CVE-2010-2443

The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereferenc…

Fix: after 3.9.2
Fix from $1,600 2010-06-24
Libtiff MEDIUM 6.8
CVE-2010-2065EPSS 6%

Integer overflow in the TIFFroundup macro in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (application crash) or possibl…

Fix: after 3.9.2
Fix from $1,600 2010-06-24
Libtiff HIGH 9.3
CVE-2009-2347

Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to exe…

Patch available
Fix from $1,950 2009-07-14
Libtiff MEDIUM 6.8
CVE-2008-2327

Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in the LZW decoder in LibTIFF 3.…

Fix: after 3.8.2
Fix from $1,600 2008-08-27
Libtiff HIGH 7.8
CVE-2006-3463

The EstimateStripByteCounts function in TIFF library (libtiff) before 3.8.2 uses a 16-bit unsigned short when iterating over an unsigned 32-bit value…

Fix: after 3.8.1
Fix from $1,950 2006-08-03
Libtiff HIGH 7.5
CVE-2006-3459EPSS 53%

Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dep…

Fix: after 3.8.1
Fix from $1,950 2006-08-03
Libtiff HIGH 7.5
CVE-2006-3460

Heap-based buffer overflow in the JPEG decoder in the TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to cause a denial of ser…

Fix: after 3.8.1
Fix from $1,950 2006-08-03
Libtiff HIGH 7.5
CVE-2006-3461EPSS 5%

Heap-based buffer overflow in the PixarLog decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbi…

Fix: after 3.8.1
Fix from $1,950 2006-08-03
Libtiff HIGH 7.5
CVE-2006-3462EPSS 5%

Heap-based buffer overflow in the NeXT RLE decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbi…

Fix: after 3.8.1
Fix from $1,950 2006-08-03
Libtiff HIGH 7.5
CVE-2006-3464

TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to pass numeric range checks and possibly execute code, and trigger assert err…

Fix: after 3.8.1
Fix from $1,950 2006-08-03
Libtiff HIGH 7.5
CVE-2006-3465EPSS 6%

Unspecified vulnerability in the custom tag support for the TIFF library (libtiff) before 3.8.2 allows remote attackers to cause a denial of service …

Fix: after 3.8.1
Fix from $1,950 2006-08-03
Libtiff HIGH 7.5
CVE-2006-2193EPSS 5%

Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) a…

Fix: after 3.8.2
Fix from $1,950 2006-06-08
Libtiff HIGH 7.5
CVE-2006-2656EPSS 14%

Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long fi…

Fix: after 3.8.2
Fix from $1,950 2006-05-30
Libtiff MEDIUM 6.5
CVE-2006-2025EPSS 11%

Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of serv…

Fix: after 3.8.0
Fix from $1,600 2006-04-25
Libtiff MEDIUM 6.5
CVE-2006-2026EPSS 10%

Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly …

Fix: after 3.8.0
Fix from $1,600 2006-04-25
Libtiff MEDIUM 5.0
CVE-2006-0405

The TIFFFetchShortPair function in tif_dirread.c in libtiff 3.8.0 allows remote attackers to cause a denial of service (application crash) via a craf…

Mitigation only
Fix from $1,600 2006-01-25
Libtiff MEDIUM 5.0
CVE-2005-2452

libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero "YCbCr subsampling" …

Mitigation only
Fix from $1,600 2005-08-03
Libtiff HIGH 7.5
CVE-2005-1544EPSS 14%

Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample …

Patch available
Fix from $1,950 2005-05-14
Libtiff HIGH 10.0
CVE-2004-0929EPSS 8%

Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPE…

Patch available
Fix from $1,950 2005-01-27
Libtiff HIGH 10.0
CVE-2004-1308EPSS 15%

Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF fil…

Patch available
Fix from $1,950 2005-01-10
Libtiff MEDIUM 5.1
CVE-2004-1183

Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and p…

Patch available
Fix from $1,600 2005-01-06