Show filters
100 Total Results
Displaying 41-50 of 100
Sort by:
Attacker Value
Unknown

CVE-2017-9404

Disclosure Date: June 02, 2017 (last updated November 26, 2024)
In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.
0
Attacker Value
Unknown

CVE-2017-9147

Disclosure Date: May 22, 2017 (last updated November 26, 2024)
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
0
Attacker Value
Unknown

CVE-2017-9117

Disclosure Date: May 21, 2017 (last updated January 08, 2025)
In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).
0
Attacker Value
Unknown

CVE-2016-10371

Disclosure Date: May 10, 2017 (last updated November 26, 2024)
The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file.
0
Attacker Value
Unknown

CVE-2017-7602

Disclosure Date: April 09, 2017 (last updated November 26, 2024)
LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
0
Attacker Value
Unknown

CVE-2017-7597

Disclosure Date: April 09, 2017 (last updated November 26, 2024)
tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
0
Attacker Value
Unknown

CVE-2017-7593

Disclosure Date: April 09, 2017 (last updated November 26, 2024)
tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.
0
Attacker Value
Unknown

CVE-2017-7595

Disclosure Date: April 09, 2017 (last updated November 26, 2024)
The JPEGSetupEncode function in tiff_jpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.
0
Attacker Value
Unknown

CVE-2017-7596

Disclosure Date: April 09, 2017 (last updated November 26, 2024)
LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
0
Attacker Value
Unknown

CVE-2017-7601

Disclosure Date: April 09, 2017 (last updated November 26, 2024)
LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
0