CVE-2025-8534
- EPSS 0.18%
- Veröffentlicht 04.08.2025 23:32:08
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to laun...
CVE-2024-13978
- EPSS 0.19%
- Veröffentlicht 01.08.2025 21:32:07
- Zuletzt bearbeitet 03.11.2025 19:15:42
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null pointer dere...
CVE-2025-8177
- EPSS 0.28%
- Veröffentlicht 26.07.2025 04:02:07
- Zuletzt bearbeitet 11.09.2025 16:57:45
A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is nam...
CVE-2025-8176
- EPSS 0.24%
- Veröffentlicht 26.07.2025 03:32:08
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached loca...
CVE-2024-7006
- EPSS 1.52%
- Veröffentlicht 12.08.2024 13:38:40
- Zuletzt bearbeitet 03.11.2025 21:18:47
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentatio...
CVE-2023-52356
- EPSS 2.19%
- Veröffentlicht 25.01.2024 20:15:39
- Zuletzt bearbeitet 10.06.2026 18:16:36
A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.
CVE-2023-52355
- EPSS 1.83%
- Veröffentlicht 25.01.2024 20:15:38
- Zuletzt bearbeitet 02.10.2026 03:16:35
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 ...
CVE-2023-6228
- EPSS 0.4%
- Veröffentlicht 18.12.2023 14:15:11
- Zuletzt bearbeitet 21.11.2024 08:43:24
An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.
CVE-2023-6277
- EPSS 1.81%
- Veröffentlicht 24.11.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:31
An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.
CVE-2023-3164
- EPSS 0.32%
- Veröffentlicht 02.11.2023 12:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:36
A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.