Show filters
251 Total Results
Displaying 51-60 of 251
Sort by:
Attacker Value
Unknown

CVE-2022-2868

Disclosure Date: August 17, 2022 (last updated October 08, 2023)
libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.
Attacker Value
Unknown

CVE-2022-2867

Disclosure Date: August 17, 2022 (last updated October 08, 2023)
libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation.
Attacker Value
Unknown

CVE-2022-34526

Disclosure Date: July 29, 2022 (last updated November 08, 2023)
A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.
Attacker Value
Unknown

CVE-2022-34266

Disclosure Date: July 19, 2022 (last updated October 07, 2023)
The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range may be passed as an argument to the memset() function within TIFFFetchStripThing() in tif_dirread.c. This will cause TIFFFetchStripThing() to segfault after use of an uninitialized resource.
Attacker Value
Unknown

CVE-2022-2058

Disclosure Date: June 30, 2022 (last updated October 07, 2023)
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
Attacker Value
Unknown

CVE-2022-2057

Disclosure Date: June 30, 2022 (last updated October 07, 2023)
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
Attacker Value
Unknown

CVE-2022-2056

Disclosure Date: June 30, 2022 (last updated October 07, 2023)
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
Attacker Value
Unknown

CVE-2022-1622

Disclosure Date: May 11, 2022 (last updated November 08, 2023)
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
Attacker Value
Unknown

CVE-2022-1623

Disclosure Date: May 11, 2022 (last updated November 08, 2023)
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
Attacker Value
Unknown

CVE-2022-1210

Disclosure Date: April 03, 2022 (last updated February 23, 2025)
A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used.