Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2020-18768

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.
Attacker Value
Unknown

CVE-2020-19144

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.
Attacker Value
Unknown

CVE-2020-19143

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'.
Attacker Value
Unknown

CVE-2020-19131

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".
Attacker Value
Unknown

CVE-2019-7663

Disclosure Date: February 09, 2019 (last updated November 27, 2024)
An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.
0
Attacker Value
Unknown

CVE-2019-6128

Disclosure Date: January 11, 2019 (last updated November 27, 2024)
The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.
Attacker Value
Unknown

CVE-2013-4231

Disclosure Date: January 19, 2014 (last updated November 08, 2023)
Multiple buffer overflows in libtiff before 4.0.3 allow remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) extension block in a GIF image or (2) GIF raster image to tools/gif2tiff.c or (3) a long filename for a TIFF image to tools/rgb2ycbcr.c. NOTE: vectors 1 and 3 are disputed by Red Hat, which states that the input cannot exceed the allocated buffer size.
0
Attacker Value
Unknown

CVE-2013-4244

Disclosure Date: September 28, 2013 (last updated October 05, 2023)
The LZW decompressor in the gif2tiff tool in libtiff 4.0.3 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted GIF image.
0
Attacker Value
Unknown

CVE-2013-4243

Disclosure Date: September 10, 2013 (last updated October 05, 2023)
Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted height and width values in a GIF image.
0
Attacker Value
Unknown

CVE-2013-1961

Disclosure Date: July 03, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the t2p_write_pdf_page function in tiff2pdf in libtiff before 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted image length and resolution in a TIFF image file.
0