Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
285 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.7% | — | Debian LinuxLibtiff | 1/2/2016 | 17/6/2026 | tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CVE-2015-8781. | |
| Modificada | Media (6.5) | 2.8% | — | Debian LinuxLibtiff | 1/2/2016 | 17/6/2026 | tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image, a different vulnerability than CVE-2015-8782. | |
| Modificada | Crítica (9.8) | 14% | — | LibtiffOracle VM ServerOracle LinuxRedhat Enterprise Linux+2 | 8/1/2016 | 17/6/2026 | Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a large width field in a BMP image. | |
| Modificada | Crítica (9.8) | 4.2% | — | Libtiff | 8/1/2016 | 17/6/2026 | The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image. | |
| Modificada | Media (5) | 4.8% | — | Libtiff | 20/1/2015 | 17/6/2026 | Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read. | |
| Modificada | Media (4.3) | 7.4% | — | Libtiff | 19/1/2014 | 16/6/2026 | Multiple buffer overflows in libtiff before 4.0.3 allow remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) extension block in a GIF image or (2) GIF raster image to tools/gif2tiff.c or (3) a long filename for a TIFF image to tools/rgb2ycbcr.c. NOTE: vectors 1 and 3 are disputed by… | |
| Modificada | Media (6.8) | 2.7% | — | Libtiff | 28/9/2013 | 16/6/2026 | The LZW decompressor in the gif2tiff tool in libtiff 4.0.3 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted GIF image. | |
| Modificada | Media (6.8) | 7.2% | — | LibtiffDebian Linux | 10/9/2013 | 16/6/2026 | Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted height and width values in a GIF image. | |
| Modificada | Media (6.8) | 5.0% | — | LibtiffDebian Linux | 10/9/2013 | 16/6/2026 | Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted TIFF image. | |
| Modificada | Alta (9.3) | 5.9% | — | Remotesensing Libtiff | 3/7/2013 | 16/6/2026 | Stack-based buffer overflow in the t2p_write_pdf_page function in tiff2pdf in libtiff before 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted image length and resolution in a TIFF image file. | |
| Modificada | Alta (9.3) | 12% | — | Remotesensing Libtiff | 3/7/2013 | 16/6/2026 | Heap-based buffer overflow in the t2p_process_jpeg_strip function in tiff2pdf in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image file. | |
| Modificada | Media (6.8) | 4.2% | — | Libtiff | 4/1/2013 | 16/6/2026 | Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image. | |
| Modificada | Media (6.8) | 14% | — | LibtiffDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+4 | 11/11/2012 | 16/6/2026 | ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM image that triggers an integer overflow, a zero-memory allocation, and a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 6.7% | — | Libtiff | 28/10/2012 | 16/6/2026 | Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF image using the PixarLog Compression format. | |
| Modificada | Media (6.8) | 4.1% | — | Libtiff | 13/8/2012 | 16/6/2026 | The t2p_read_tiff_init function in tiff2pdf (tools/tiff2pdf.c) in LibTIFF 4.0.2 and earlier does not properly initialize the T2P context struct pointer in certain error conditions, which allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image… | |
| Modificada | Media (6.8) | 5.5% | — | Libtiff | 22/7/2012 | 16/6/2026 | Multiple integer overflows in tiff2pdf in libtiff before 4.0.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 6.5% | — | Libtiff | 22/7/2012 | 16/6/2026 | Integer signedness error in the TIFFReadDirectory function in tif_dirread.c in libtiff 3.9.4 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a negative tile depth in a tiff image, which triggers an improper conversion between signed and… | |
| Modificada | Media (6.8) | 6.9% | — | Libtiff | 4/6/2012 | 16/6/2026 | Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow. | |
| Modificada | Media (4.3) | 2.6% | — | Libtiff | 3/5/2011 | 16/6/2026 | Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a directory data structure with many directory entries. | |
| Modificada | Media (6.8) | 11% | 💥 Exploit | Libtiff | 3/5/2011 | 16/6/2026 | Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file. | |
| Modificada | Media (6.8) | 6.2% | — | Libtiff | 28/3/2011 | 16/6/2026 | Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value. | |
| Modificada | Media (6.8) | 3.2% | — | LibtiffOpensuse | 28/9/2010 | 16/6/2026 | LibTIFF before 3.9.2-5.2.1 in SUSE openSUSE 11.3 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted TIFF image. | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Libtiff | 6/7/2010 | 16/6/2026 | LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481. | |
| Modificada | Media (4.3) | 5.0% | 💥 Exploit | Libtiff | 6/7/2010 | 16/6/2026 | The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481. | |
| Modificada | Media (4.3) | 2.0% | — | Libtiff | 6/7/2010 | 16/6/2026 | The TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a TIFF file with an invalid combination of SamplesPerPixel and Photometric values. |