Libtiff

Libtiff

265 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.14%
  • Veröffentlicht 22.11.2016 19:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.

  • EPSS 3.14%
  • Veröffentlicht 22.11.2016 19:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip(). Reported as MSVR 35098, aka "t2p_process_jpeg_strip heap-buffer-overflow."

Medienbericht
  • EPSS 4.77%
  • Veröffentlicht 22.11.2016 19:59:03
  • Zuletzt bearbeitet 29.05.2026 21:16:30

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Pre...

Exploit
  • EPSS 3.55%
  • Veröffentlicht 22.11.2016 19:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members. Reported as MSVR 35095, aka "TIFFFlushData1 heap-buffer-overflow."

  • EPSS 3.19%
  • Veröffentlicht 22.11.2016 19:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers. Reported as MSVR 35094, aka "PixarLog horizontalDifference heap-buffer-overflow."

Exploit
  • EPSS 6.59%
  • Veröffentlicht 28.10.2016 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be trigge...

  • EPSS 4%
  • Veröffentlicht 03.10.2016 16:09:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving the ma variable.

  • EPSS 1.68%
  • Veröffentlicht 03.10.2016 16:09:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.

  • EPSS 1.61%
  • Veröffentlicht 03.10.2016 16:09:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The setrow function in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the src variable.

  • EPSS 2.59%
  • Veröffentlicht 03.10.2016 16:09:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The (1) cpStrips and (2) cpTiles functions in the thumbnail tool in LibTIFF 4.0.6 and earlier allow remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the bytecounts[] array variable.