Show filters
251 Total Results
Displaying 91-100 of 251
Sort by:
Attacker Value
Unknown

CVE-2018-10963

Disclosure Date: May 10, 2018 (last updated November 26, 2024)
The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726.
0
Attacker Value
Unknown

CVE-2018-10801

Disclosure Date: May 08, 2018 (last updated November 26, 2024)
TIFFClientOpen in tif_unix.c in LibTIFF 3.8.2 has memory leaks, as demonstrated by bmp2tiff.
0
Attacker Value
Unknown

CVE-2018-10779

Disclosure Date: May 07, 2018 (last updated November 26, 2024)
TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.
0
Attacker Value
Unknown

CVE-2018-10126

Disclosure Date: April 21, 2018 (last updated August 20, 2024)
ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.
Attacker Value
Unknown

CVE-2018-8905

Disclosure Date: March 22, 2018 (last updated November 26, 2024)
In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps.
Attacker Value
Unknown

CVE-2014-8129

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.
0
Attacker Value
Unknown

CVE-2014-8130

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
0
Attacker Value
Unknown

CVE-2016-5314

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.
0
Attacker Value
Unknown

CVE-2018-7456

Disclosure Date: February 24, 2018 (last updated November 26, 2024)
A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013. (This affects an earlier part of the TIFFPrintDirectory function that was not addressed by the CVE-2017-18013 patch.)
0
Attacker Value
Unknown

CVE-2018-5784

Disclosure Date: January 19, 2018 (last updated November 26, 2024)
In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.
0