Show filters
266 Total Results
Displaying 1-10 of 266
Sort by:
Attacker Value
Unknown

CVE-2024-7006

Disclosure Date: August 12, 2024 (last updated November 06, 2024)
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.
Attacker Value
Unknown

CVE-2024-24792

Disclosure Date: June 27, 2024 (last updated June 28, 2024)
Parsing a corrupt or malicious image with invalid color indices can cause a panic.
0
Attacker Value
Unknown

CVE-2024-0080

Disclosure Date: April 05, 2024 (last updated April 10, 2024)
NVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead to a partial denial of service.
0
Attacker Value
Unknown

CVE-2023-52356

Disclosure Date: January 25, 2024 (last updated August 07, 2024)
A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.
Attacker Value
Unknown

CVE-2023-52355

Disclosure Date: January 25, 2024 (last updated April 25, 2024)
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
Attacker Value
Unknown

CVE-2023-6228

Disclosure Date: December 18, 2023 (last updated October 12, 2024)
An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.
Attacker Value
Unknown

CVE-2023-6352

Disclosure Date: November 30, 2023 (last updated December 12, 2023)
The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may be able to enumerate files or directories, traverse directories, bypass authentication, or access restricted files.
Attacker Value
Unknown

CVE-2023-6277

Disclosure Date: November 24, 2023 (last updated April 25, 2024)
An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.
Attacker Value
Unknown

CVE-2023-3164

Disclosure Date: November 02, 2023 (last updated March 09, 2024)
A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.
Attacker Value
Unknown

CVE-2023-41175

Disclosure Date: October 05, 2023 (last updated April 30, 2024)
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.