Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
275 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 11% | 💥 Exploit | Libtiff | 2/12/2017 | 17/6/2026 | tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file. | |
| Modificada | Media (6.5) | 2.3% | — | Libtiff | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Media (6.5) | 2.6% | — | Libtiff | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Alta (7.5) | 2.7% | — | Libtiff | 18/8/2017 | 17/6/2026 | The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to cause a denial of service (allocation failure and application crash) in the TIFFFetchStripThing function in tif_dirread.c during a tiff2pdf invocation. | |
| Modificada | Media (6.5) | 2.7% | — | Libtiff | 26/7/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a denial of service attack. During the TIFFOpen process, td_imagelength is not checked. The value of td_imagelength can be directly controlled by an input file. In the ChopUpSingleUncompressedStrip… | |
| Modificada | Alta (8.8) | 3.9% | — | Libtiff | 17/7/2017 | 17/6/2026 | There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred bytes out-of-bounds write (related to the ZIPDecode function in tif_zip.c). A crafted input may lead to a remote denial of service attack or an arbitrary code execution… | |
| Modificada | Alta (7.5) | 7.4% | 💥 Exploit | Libtiff | 29/6/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Media (6.5) | 5.7% | — | LibtiffOpensuse | 26/6/2017 | 17/6/2026 | LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the… | |
| Modificada | Media (6.5) | 3.0% | — | Libtiff | 26/6/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack. | |
| Modificada | Media (6.5) | 7.5% | 💥 Exploit | LibtiffDebian LinuxCanonical Ubuntu Linux | 26/6/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack. | |
| Modificada | Alta (8.8) | 3.9% | — | LibtiffCanonical Ubuntu LinuxDebian Linux | 26/6/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bounds read in TIFFCleanup, an invalid free in TIFFClose or t2p_free, memory corruption in… | |
| Modificada | Media (6.5) | 1.6% | — | LibtiffCanonical Ubuntu Linux | 22/6/2017 | 17/6/2026 | In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function _TIFFmalloc in tif_unix.c) via a crafted file. | |
| Modificada | Media (6.5) | 1.5% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 2/6/2017 | 17/6/2026 | In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Media (6.5) | 1.2% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 2/6/2017 | 17/6/2026 | In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Media (6.5) | 7.0% | 💥 Exploit | Libtiff | 22/5/2017 | 17/6/2026 | LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file. | |
| Modificada | Media (4) | 2.2% | — | LibtiffCanonical Ubuntu Linux | 21/5/2017 | 17/6/2026 | In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the… | |
| Modificada | Media (5.5) | 1.0% | — | Libtiff | 10/5/2017 | 17/6/2026 | The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file. | |
| Modificada | Media (5.5) | 1.6% | — | LibtiffDebian Linux | 11/4/2017 | 17/6/2026 | The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image. | |
| Modificada | Alta (7.8) | 2.7% | — | Libtiff | 9/4/2017 | 17/6/2026 | LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. | |
| Modificada | Alta (7.8) | 2.5% | — | Libtiff | 9/4/2017 | 17/6/2026 | LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. | |
| Modificada | Alta (7.8) | 1.5% | — | Libtiff | 9/4/2017 | 17/6/2026 | LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. | |
| Modificada | Alta (7.8) | 2.0% | — | Libtiff | 9/4/2017 | 17/6/2026 | LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. | |
| Modificada | Alta (7.8) | 2.5% | — | Libtiff | 9/4/2017 | 17/6/2026 | tif_dirread.c in LibTIFF 4.0.7 might allow remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image. | |
| Modificada | Alta (7.8) | 1.8% | — | Libtiff | 9/4/2017 | 17/6/2026 | tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. | |
| Modificada | Alta (7.8) | 1.9% | — | Libtiff | 9/4/2017 | 17/6/2026 | LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. |