CVE-2026-52491
- EPSS 0.17%
- Veröffentlicht 25.08.2026 21:17:01
- Zuletzt bearbeitet 09.09.2026 16:03:22
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component
CVE-2026-52492
- EPSS 0.16%
- Veröffentlicht 24.08.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:03:22
An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image
CVE-2026-52490
- EPSS 0.4%
- Veröffentlicht 24.08.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:03:22
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
CVE-2026-4775
- EPSS 0.55%
- Veröffentlicht 24.03.2026 14:42:47
- Zuletzt bearbeitet 02.10.2026 02:17:02
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write du...
CVE-2025-61143
- EPSS 0.11%
- Veröffentlicht 23.02.2026 00:00:00
- Zuletzt bearbeitet 25.02.2026 15:20:49
libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
CVE-2025-61144
- EPSS 0.25%
- Veröffentlicht 23.02.2026 00:00:00
- Zuletzt bearbeitet 25.02.2026 15:20:50
libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.
- EPSS 0.13%
- Veröffentlicht 23.02.2026 00:00:00
- Zuletzt bearbeitet 25.02.2026 15:20:50
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
CVE-2025-9165
- EPSS 0.21%
- Veröffentlicht 19.08.2025 20:02:13
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restri...
CVE-2025-8961
- EPSS 0.2%
- Veröffentlicht 14.08.2025 12:02:08
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made...
CVE-2025-8851
- EPSS 0.18%
- Veröffentlicht 11.08.2025 13:32:08
- Zuletzt bearbeitet 30.10.2025 21:10:36
A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is r...