Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2009-5022
Disclosure Date: May 03, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.
0
Attacker Value
Unknown
CVE-2011-1167
Disclosure Date: March 28, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.
0
Attacker Value
Unknown
CVE-2010-2483
Disclosure Date: July 06, 2010 (last updated October 04, 2023)
The TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a TIFF file with an invalid combination of SamplesPerPixel and Photometric values.
0
Attacker Value
Unknown
CVE-2010-2481
Disclosure Date: July 06, 2010 (last updated October 04, 2023)
The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly handle unknown tag types in TIFF directory entries, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF file.
0
Attacker Value
Unknown
CVE-2010-2631
Disclosure Date: July 06, 2010 (last updated October 04, 2023)
LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.
0
Attacker Value
Unknown
CVE-2010-2630
Disclosure Date: July 06, 2010 (last updated October 04, 2023)
The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.
0
Attacker Value
Unknown
CVE-2010-2482
Disclosure Date: July 06, 2010 (last updated October 04, 2023)
LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.
0
Attacker Value
Unknown
CVE-2010-2597
Disclosure Date: July 02, 2010 (last updated October 04, 2023)
The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image, related to "downsampled OJPEG input" and possibly related to a compiler optimization that triggers a divide-by-zero error.
0
Attacker Value
Unknown
CVE-2010-2595
Disclosure Date: July 02, 2010 (last updated October 04, 2023)
The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ImageMagick, does not properly handle invalid ReferenceBlackWhite values, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers an array index error, related to "downsampled OJPEG input."
0
Attacker Value
Unknown
CVE-2010-2233
Disclosure Date: July 02, 2010 (last updated October 04, 2023)
tif_getimage.c in LibTIFF 3.9.0 and 3.9.2 on 64-bit platforms, as used in ImageMagick, does not properly perform vertical flips, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TIFF image, related to "downsampled OJPEG input."
0