Show filters
257 Total Results
Displaying 101-110 of 257
Sort by:
Attacker Value
Unknown

CVE-2016-5314

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.
0
Attacker Value
Unknown

CVE-2018-7456

Disclosure Date: February 24, 2018 (last updated November 26, 2024)
A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013. (This affects an earlier part of the TIFFPrintDirectory function that was not addressed by the CVE-2017-18013 patch.)
0
Attacker Value
Unknown

CVE-2018-5784

Disclosure Date: January 19, 2018 (last updated November 26, 2024)
In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.
0
Attacker Value
Unknown

CVE-2018-5360

Disclosure Date: January 14, 2018 (last updated November 26, 2024)
LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.
0
Attacker Value
Unknown

CVE-2017-18013

Disclosure Date: January 01, 2018 (last updated November 26, 2024)
In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.
0
Attacker Value
Unknown

CVE-2017-17973

Disclosure Date: December 29, 2017 (last updated November 08, 2023)
In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue
0
Attacker Value
Unknown

CVE-2017-17942

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c.
0
Attacker Value
Unknown

CVE-2017-17095

Disclosure Date: December 02, 2017 (last updated November 26, 2024)
tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.
0
Attacker Value
Unknown

CVE-2017-13727

Disclosure Date: August 29, 2017 (last updated November 26, 2024)
There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
0
Attacker Value
Unknown

CVE-2017-13726

Disclosure Date: August 29, 2017 (last updated November 26, 2024)
There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
0