Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
285 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.1% | — | Aquaforest Tiff Server | 30/11/2023 | 17/6/2026 | The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may be able to enumerate files or… | |
| Modificada | Media (6.5) | 1.8% | — | LibtiffFedoraproject Fedora | 24/11/2023 | 17/6/2026 | An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB. | |
| Modificada | Media (5.5) | 0.32% | — | LibtiffRedhat Enterprise Linux | 2/11/2023 | 17/6/2026 | A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file. | |
| Modificada | Media (6.5) | 1.3% | — | LibtiffFedoraproject FedoraRedhat Enterprise Linux | 5/10/2023 | 17/6/2026 | A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 1.4% | — | LibtiffNetapp Active IQ Unified ManagerFedoraproject FedoraRedhat Enterprise Linux | 5/10/2023 | 17/6/2026 | LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. | |
| Modificada | Media (5.5) | 0.35% | — | LibtiffFedoraproject FedoraRedhat Enterprise Linux | 4/10/2023 | 23/6/2026 | A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an application crash, eventually leading to a denial of service. | |
| Modificada | Media (6.5) | 0.95% | — | Libtiff | 22/8/2023 | 17/6/2026 | An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file. | |
| Modificada | Media (5.5) | 0.28% | — | Libtiff | 22/8/2023 | 17/6/2026 | There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file. | |
| Modificada | Media (6.5) | 1.2% | — | LibtiffDebian LinuxRedhat Enterprise Linux | 12/7/2023 | 17/6/2026 | A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.42% | — | Libtiff | 30/6/2023 | 17/6/2026 | A null pointer dereference issue was found in Libtiff's tif_dir.c file. This issue may allow an attacker to pass a crafted TIFF image file to the tiffcp utility which triggers a runtime error that causes undefined behavior. This will result in an application crash, eventually leading to a denial of service. | |
| Modificada | Media (5.5) | 0.42% | — | Libtiff | 29/6/2023 | 17/6/2026 | libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian. | |
| Modificada | Media (5.5) | 0.41% | — | Libtiff | 29/6/2023 | 17/6/2026 | libtiff 4.5.0 is vulnerable to Buffer Overflow via /libtiff/tools/tiffcrop.c:8499. Incorrect updating of buffer size after rotateImage() in tiffcrop cause heap-buffer-overflow and SEGV. | |
| Modificada | Media (5.5) | 0.34% | — | Libtiff | 21/6/2023 | 17/6/2026 | libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753. | |
| Modificada | Media (6.5) | 1.1% | — | Libtiff | 19/6/2023 | 17/6/2026 | A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones. | |
| Modificada | Media (5.5) | 0.37% | — | Libtiff | 14/6/2023 | 17/6/2026 | loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image. | |
| Modificada | Alta (8.8) | 0.84% | — | Libtiff | 14/6/2023 | 17/6/2026 | libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215. | |
| Modificada | Media (5.5) | 0.30% | — | Libtiff | 19/5/2023 | 17/6/2026 | A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c. | |
| Analizada | Media (5.5) | 0.51% | — | LibtiffApple Macos | 19/5/2023 | 17/6/2026 | A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values. | |
| Modificada | Media (5.5) | 0.43% | — | LibtiffFedoraproject FedoraRedhat Enterprise Linux | 17/5/2023 | 17/6/2026 | A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service. | |
| Modificada | Media (5.5) | 0.31% | — | Libtiff | 9/5/2023 | 9/7/2026 | Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c. | |
| Modificada | Media (6.1) | 0.36% | — | Libtiff | 10/4/2023 | 17/6/2026 | A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x. | |
| Modificada | Alta (7.8) | 0.35% | — | Tinytiff Project Tinytiff | 4/4/2023 | 17/6/2026 | Buffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyTiffReader_readNextFrame function in tinytiffreader.c file. | |
| Modificada | Media (5.5) | 0.41% | — | Tinytiff Project Tinytiff | 22/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in TinyTIFF 3.0.0.0. This issue affects some unknown processing of the file tinytiffreader.c of the component File Handler. The manipulation leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public… | |
| Modificada | Media (5.5) | 0.43% | — | Fedoraproject FedoraLibtiff | 3/3/2023 | 17/6/2026 | LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125. | |
| Modificada | Media (5.5) | 0.31% | — | Golang ImageGolang TiffFedoraproject Fedora | 28/2/2023 | 17/6/2026 | An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service. |