Show filters
266 Total Results
Displaying 21-30 of 266
Sort by:
Attacker Value
Unknown

CVE-2023-26965

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.
Attacker Value
Unknown

CVE-2023-25434

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.
Attacker Value
Unknown

CVE-2023-30775

Disclosure Date: May 19, 2023 (last updated October 08, 2023)
A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.
Attacker Value
Unknown

CVE-2023-30774

Disclosure Date: May 19, 2023 (last updated January 09, 2024)
A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values.
Attacker Value
Unknown

CVE-2023-2731

Disclosure Date: May 17, 2023 (last updated October 08, 2023)
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
Attacker Value
Unknown

CVE-2023-30086

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.
Attacker Value
Unknown

CVE-2023-1916

Disclosure Date: April 10, 2023 (last updated October 08, 2023)
A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.
Attacker Value
Unknown

CVE-2023-26733

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyTiffReader_readNextFrame function in tinytiffreader.c file.
Attacker Value
Unknown

CVE-2023-1560

Disclosure Date: March 22, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, has been found in TinyTIFF 3.0.0.0. This issue affects some unknown processing of the file tinytiffreader.c of the component File Handler. The manipulation leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-223553 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-4645

Disclosure Date: March 03, 2023 (last updated October 08, 2023)
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.