Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
275 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.9% | — | LibtiffCanonical Ubuntu LinuxOpensuse LeapDebian Linux | 11/1/2019 | 17/6/2026 | The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb. | |
| Modificada | Media (6.5) | 3.6% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 12/11/2018 | 17/6/2026 | In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset. | |
| Modificada | Media (6.5) | 2.9% | — | LibtiffCanonical Ubuntu Linux | 26/10/2018 | 17/6/2026 | An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c. | |
| Modificada | Alta (8.8) | 15% | 💥 Exploit | LibtiffDebian LinuxCanonical Ubuntu Linux | 22/10/2018 | 17/6/2026 | LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring the buffer size, which leads to a tif_jbig.c JBIGDecode… | |
| Modificada | Alta (8.8) | 4.1% | — | Libtiff | 30/9/2018 | 17/6/2026 | The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935. | |
| Modificada | Alta (8.8) | 3.1% | — | Debian LinuxLibtiffCanonical Ubuntu Linux | 16/9/2018 | 17/6/2026 | An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file. | |
| Modificada | Alta (8.8) | 2.5% | — | Debian LinuxLibtiffCanonical Ubuntu Linux | 16/9/2018 | 17/6/2026 | An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file. | |
| Modificada | Media (6.5) | 3.3% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 13/9/2018 | 17/6/2026 | A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This vulnerability can be triggered by the executable tiffcp. | |
| Modificada | Alta (8.8) | 2.6% | — | LibtiffDebian Linux | 2/9/2018 | 17/6/2026 | newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf. This is a different… | |
| Modificada | Alta (8.8) | 4.0% | — | LibtiffDebian Linux | 8/8/2018 | 17/6/2026 | ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf. | |
| Modificada | Alta (8.8) | 25% | — | LibtiffCanonical Ubuntu Linux | 26/6/2018 | 17/6/2026 | Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 allows remote attackers to cause a denial of service… | |
| Modificada | Media (6.5) | 3.7% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 10/5/2018 | 17/6/2026 | The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726. | |
| Modificada | Media (6.5) | 1.1% | — | Libtiff | 8/5/2018 | 17/6/2026 | TIFFClientOpen in tif_unix.c in LibTIFF 3.8.2 has memory leaks, as demonstrated by bmp2tiff. | |
| Modificada | Media (6.5) | 2.9% | — | LibtiffCanonical Ubuntu Linux | 7/5/2018 | 17/6/2026 | TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff. | |
| Modificada | Media (6.5) | 1.8% | — | Libtiff | 21/4/2018 | 17/6/2026 | ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c. | |
| Modificada | Alta (8.8) | 3.1% | — | LibtiffDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+2 | 22/3/2018 | 17/6/2026 | In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps. | |
| Modificada | Alta (8.8) | 4.4% | — | LibtiffOpensuse LeapOpensuseRedhat Enterprise Linux+1 | 12/3/2018 | 17/6/2026 | Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr. | |
| Modificada | Media (6.5) | 3.8% | — | LibtiffRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+5 | 12/3/2018 | 17/6/2026 | The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither. | |
| Modificada | Alta (8.8) | 3.8% | — | LibtiffDebian LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+4 | 12/3/2018 | 17/6/2026 | LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c. | |
| Modificada | Media (6.5) | 3.0% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 24/2/2018 | 17/6/2026 | A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF… | |
| Modificada | Media (6.5) | 3.0% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 19/1/2018 | 17/6/2026 | In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number… | |
| Modificada | Alta (8.8) | 1.8% | — | LibtiffGraphicsmagick | 14/1/2018 | 17/6/2026 | LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27. | |
| Modificada | Media (6.5) | 2.9% | — | Libtiff | 1/1/2018 | 17/6/2026 | In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash. | |
| Modificada | Alta (8.8) | 3.1% | — | Libtiff | 29/12/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue | |
| Modificada | Alta (8.8) | 2.4% | — | Libtiff | 28/12/2017 | 17/6/2026 | In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c. |