Libtiff

Libtiff

262 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 16.56%
  • Veröffentlicht 03.05.2011 20:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.

  • EPSS 2.31%
  • Veröffentlicht 03.05.2011 20:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a d...

  • EPSS 5.53%
  • Veröffentlicht 28.03.2011 16:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSamp...

  • EPSS 1.79%
  • Veröffentlicht 28.09.2010 18:00:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

LibTIFF before 3.9.2-5.2.1 in SUSE openSUSE 11.3 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted TIFF image.

  • EPSS 3.94%
  • Veröffentlicht 06.07.2010 17:17:20
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a c...

Exploit
  • EPSS 5.37%
  • Veröffentlicht 06.07.2010 17:17:20
  • Zuletzt bearbeitet 29.04.2026 01:13:23

LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a denial of service (application crash) via a crafted fi...

Exploit
  • EPSS 1.61%
  • Veröffentlicht 06.07.2010 17:17:13
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly handle unknown tag types in TIFF directory entries, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF file.

Exploit
  • EPSS 18.83%
  • Veröffentlicht 06.07.2010 17:17:13
  • Zuletzt bearbeitet 29.04.2026 01:13:23

LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than...

  • EPSS 1.27%
  • Veröffentlicht 06.07.2010 17:17:13
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a TIFF file with an invalid combination of SamplesPerPixel and Photometric values.

Exploit
  • EPSS 1.75%
  • Veröffentlicht 02.07.2010 12:43:53
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ImageMagick, does not properly handle invalid ReferenceBlackWhite values, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that ...