Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
285 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.1% | — | LibtiffDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+2 | 22/3/2018 | 17/6/2026 | In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps. | |
| Modificada | Alta (8.8) | 4.4% | — | LibtiffOpensuse LeapOpensuseRedhat Enterprise Linux+1 | 12/3/2018 | 17/6/2026 | Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr. | |
| Modificada | Media (6.5) | 3.8% | — | LibtiffRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+5 | 12/3/2018 | 17/6/2026 | The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither. | |
| Modificada | Alta (8.8) | 3.8% | — | LibtiffDebian LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+4 | 12/3/2018 | 17/6/2026 | LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c. | |
| Modificada | Media (6.5) | 3.0% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 24/2/2018 | 17/6/2026 | A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF… | |
| Modificada | Media (6.5) | 3.0% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 19/1/2018 | 17/6/2026 | In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number… | |
| Modificada | Alta (8.8) | 1.8% | — | LibtiffGraphicsmagick | 14/1/2018 | 17/6/2026 | LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27. | |
| Modificada | Media (6.5) | 2.9% | — | Libtiff | 1/1/2018 | 17/6/2026 | In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash. | |
| Modificada | Alta (8.8) | 3.1% | — | Libtiff | 29/12/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue | |
| Modificada | Alta (8.8) | 2.4% | — | Libtiff | 28/12/2017 | 17/6/2026 | In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c. | |
| Modificada | Alta (8.8) | 11% | 💥 Exploit | Libtiff | 2/12/2017 | 17/6/2026 | tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file. | |
| Modificada | Media (6.5) | 2.3% | — | Libtiff | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Media (6.5) | 2.6% | — | Libtiff | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Alta (7.5) | 2.7% | — | Libtiff | 18/8/2017 | 17/6/2026 | The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to cause a denial of service (allocation failure and application crash) in the TIFFFetchStripThing function in tif_dirread.c during a tiff2pdf invocation. | |
| Modificada | Media (6.5) | 2.7% | — | Libtiff | 26/7/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a denial of service attack. During the TIFFOpen process, td_imagelength is not checked. The value of td_imagelength can be directly controlled by an input file. In the ChopUpSingleUncompressedStrip… | |
| Modificada | Alta (8.8) | 3.9% | — | Libtiff | 17/7/2017 | 17/6/2026 | There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred bytes out-of-bounds write (related to the ZIPDecode function in tif_zip.c). A crafted input may lead to a remote denial of service attack or an arbitrary code execution… | |
| Modificada | Alta (7.5) | 7.4% | 💥 Exploit | Libtiff | 29/6/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Media (6.5) | 5.7% | — | LibtiffOpensuse | 26/6/2017 | 17/6/2026 | LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the… | |
| Modificada | Media (6.5) | 3.0% | — | Libtiff | 26/6/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack. | |
| Modificada | Media (6.5) | 7.5% | 💥 Exploit | LibtiffDebian LinuxCanonical Ubuntu Linux | 26/6/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack. | |
| Modificada | Alta (8.8) | 3.9% | — | LibtiffCanonical Ubuntu LinuxDebian Linux | 26/6/2017 | 17/6/2026 | In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bounds read in TIFFCleanup, an invalid free in TIFFClose or t2p_free, memory corruption in… | |
| Modificada | Media (6.5) | 1.6% | — | LibtiffCanonical Ubuntu Linux | 22/6/2017 | 17/6/2026 | In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function _TIFFmalloc in tif_unix.c) via a crafted file. | |
| Modificada | Media (6.5) | 1.5% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 2/6/2017 | 17/6/2026 | In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Media (6.5) | 1.2% | — | LibtiffDebian LinuxCanonical Ubuntu Linux | 2/6/2017 | 17/6/2026 | In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Media (6.5) | 7.0% | 💥 Exploit | Libtiff | 22/5/2017 | 17/6/2026 | LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file. |