Show filters
100 Total Results
Displaying 41-50 of 100
Sort by:
Attacker Value
Unknown
CVE-2017-9404
Disclosure Date: June 02, 2017 (last updated November 26, 2024)
In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.
0
Attacker Value
Unknown
CVE-2017-9147
Disclosure Date: May 22, 2017 (last updated November 26, 2024)
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
0
Attacker Value
Unknown
CVE-2017-9117
Disclosure Date: May 21, 2017 (last updated January 08, 2025)
In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).
0
Attacker Value
Unknown
CVE-2016-10371
Disclosure Date: May 10, 2017 (last updated November 26, 2024)
The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file.
0
Attacker Value
Unknown
CVE-2017-7602
Disclosure Date: April 09, 2017 (last updated November 26, 2024)
LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
0
Attacker Value
Unknown
CVE-2017-7597
Disclosure Date: April 09, 2017 (last updated November 26, 2024)
tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
0
Attacker Value
Unknown
CVE-2017-7593
Disclosure Date: April 09, 2017 (last updated November 26, 2024)
tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.
0
Attacker Value
Unknown
CVE-2017-7595
Disclosure Date: April 09, 2017 (last updated November 26, 2024)
The JPEGSetupEncode function in tiff_jpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.
0
Attacker Value
Unknown
CVE-2017-7596
Disclosure Date: April 09, 2017 (last updated November 26, 2024)
LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
0
Attacker Value
Unknown
CVE-2017-7601
Disclosure Date: April 09, 2017 (last updated November 26, 2024)
LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
0