Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
285 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.6% | — | LibtiffNetapp Ontap Select Deploy Administration UtilityFedoraproject FedoraRedhat Enterprise Linux | 9/3/2021 | 17/6/2026 | In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack. | |
| Modificada | Media (5.5) | 1.2% | — | LibtiffRedhat Enterprise LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 9/3/2021 | 17/6/2026 | A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service. | |
| Modificada | Alta (7.5) | 1.8% | — | Aquaforest Tiff Server | 18/3/2020 | 17/6/2026 | Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download. | |
| Modificada | Alta (7.5) | 1.4% | — | Aquaforest Tiff Server | 18/3/2020 | 17/6/2026 | Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC. | |
| Modificada | Media (5.3) | 1.6% | — | Aquaforest Tiff Server | 18/3/2020 | 17/6/2026 | Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx. | |
| Modificada | Media (6.5) | 3.9% | — | Libtiff | 12/2/2020 | 17/6/2026 | LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image. | |
| Modificada | Alta (8.8) | 3.4% | — | LibtiffOsgeo Gdal | 14/10/2019 | 17/6/2026 | tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition. | |
| Modificada | Media (6.5) | 4.2% | — | LibtiffDebian LinuxFedoraproject FedoraOpensuse Leap | 14/8/2019 | 17/6/2026 | _TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash. | |
| Modificada | Alta (7.5) | 5.6% | — | LibtiffOpensuse LeapSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 21/3/2019 | 17/6/2026 | LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue | |
| Modificada | Media (6.5) | 3.4% | — | LibtiffDebian LinuxCanonical Ubuntu LinuxOpensuse Leap | 9/2/2019 | 17/6/2026 | An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different… | |
| Modificada | Alta (8.8) | 3.9% | — | LibtiffCanonical Ubuntu LinuxOpensuse LeapDebian Linux | 11/1/2019 | 17/6/2026 | The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb. | |
| Modificada | Media (6.5) | 3.6% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 12/11/2018 | 17/6/2026 | In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset. | |
| Modificada | Media (6.5) | 2.9% | — | LibtiffCanonical Ubuntu Linux | 26/10/2018 | 17/6/2026 | An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c. | |
| Modificada | Alta (8.8) | 15% | 💥 Exploit | LibtiffDebian LinuxCanonical Ubuntu Linux | 22/10/2018 | 17/6/2026 | LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring the buffer size, which leads to a tif_jbig.c JBIGDecode… | |
| Modificada | Alta (8.8) | 4.1% | — | Libtiff | 30/9/2018 | 17/6/2026 | The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935. | |
| Modificada | Alta (8.8) | 3.1% | — | Debian LinuxLibtiffCanonical Ubuntu Linux | 16/9/2018 | 17/6/2026 | An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file. | |
| Modificada | Alta (8.8) | 2.5% | — | Debian LinuxLibtiffCanonical Ubuntu Linux | 16/9/2018 | 17/6/2026 | An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file. | |
| Modificada | Media (6.5) | 3.3% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 13/9/2018 | 17/6/2026 | A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This vulnerability can be triggered by the executable tiffcp. | |
| Modificada | Alta (8.8) | 2.6% | — | LibtiffDebian Linux | 2/9/2018 | 17/6/2026 | newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf. This is a different… | |
| Modificada | Alta (8.8) | 4.0% | — | LibtiffDebian Linux | 8/8/2018 | 17/6/2026 | ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf. | |
| Modificada | Alta (8.8) | 25% | — | LibtiffCanonical Ubuntu Linux | 26/6/2018 | 17/6/2026 | Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 allows remote attackers to cause a denial of service… | |
| Modificada | Media (6.5) | 3.7% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 10/5/2018 | 17/6/2026 | The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726. | |
| Modificada | Media (6.5) | 1.1% | — | Libtiff | 8/5/2018 | 17/6/2026 | TIFFClientOpen in tif_unix.c in LibTIFF 3.8.2 has memory leaks, as demonstrated by bmp2tiff. | |
| Modificada | Media (6.5) | 2.9% | — | LibtiffCanonical Ubuntu Linux | 7/5/2018 | 17/6/2026 | TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff. | |
| Modificada | Media (6.5) | 1.8% | — | Libtiff | 21/4/2018 | 17/6/2026 | ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c. |