Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
275 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.53% | — | OpenslideAILibtiffAI | 17/9/2026 | 23/9/2026 | OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in src/openslide-decode-tiff.c and _openslide_tiff_read_tile() to request a full-height destination for a partial bottom tile row, allowing uninitialized heap memory to… | |
| Pendiente de análisis | Media (6.1) | 0.12% | — | LibtiffAILibtiff Tiff2pdfAI | 11/9/2026 | 16/9/2026 | A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads… | |
| Pendiente de análisis | Alta (8.4) | 0.19% | — | LibtiffAI | 25/8/2026 | 9/9/2026 | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | LibtiffAI | 24/8/2026 | 9/9/2026 | An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image | |
| Pendiente de análisis | Crítica (9.8) | 0.51% | — | LibtiffAI | 24/8/2026 | 9/9/2026 | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c | |
| Pendiente de análisis | Alta (7.3) | 0.43% | — | LibtiffAI | 29/6/2026 | 1/10/2026 | A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow.… | |
| Modificada | Alta (7.8) | 0.38% | — | LibtiffRedhat Hardened ImagesDebian LinuxRedhat Enterprise Linux | 24/3/2026 | 15/7/2026 | A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a… | |
| Modificada | Media (5) | 0.14% | — | Libtiff | 23/2/2026 | 17/6/2026 | libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c. | |
| Modificada | Alta (7.3) | 0.26% | — | Libtiff | 23/2/2026 | 17/6/2026 | libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function. | |
| Modificada | Media (5.5) | 0.12% | — | Libtiff | 23/2/2026 | 17/6/2026 | libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c. | |
| Aplazada | Alta (8.8) | 0.97% | — | LibtiffAI | 23/9/2025 | 26/9/2026 | A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an… | |
| Modificada | Baja (1.1) | 0.22% | — | Libtiff | 19/8/2025 | 17/6/2026 | A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high… | |
| Analizada | Baja (1.9) | 0.21% | — | Libtiff | 14/8/2025 | 17/6/2026 | A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited. | |
| Analizada | Media (4.8) | 0.18% | — | Libtiff | 11/8/2025 | 17/6/2026 | A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as… | |
| Analizada | Baja (1.1) | 0.19% | — | Libtiff | 5/8/2025 | 17/6/2026 | A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is… | |
| Modificada | Baja (2) | 0.19% | — | Libtiff | 1/8/2025 | 17/6/2026 | A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The complexity of… | |
| Analizada | Media (4.8) | 0.29% | — | Libtiff | 26/7/2025 | 17/6/2026 | A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to… | |
| Analizada | Baja (1.9) | 0.25% | — | Libtiff | 26/7/2025 | 17/6/2026 | A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (7.5) | 1.5% | — | LibtiffRedhat Enterprise LinuxRedhat Enterprise Linux FOR ARM 64Redhat Enterprise Linux FOR Power Little Endian EUS+1 | 12/8/2024 | 17/6/2026 | A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a… | |
| Modificada | Alta (7.5) | 2.2% | — | LibtiffRedhat Enterprise Linux | 25/1/2024 | 17/6/2026 | A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service. | |
| Modificada | Alta (7.5) | 1.8% | — | LibtiffRedhat Enterprise Linux | 25/1/2024 | 1/10/2026 | An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB. | |
| Modificada | Media (5.5) | 0.40% | — | Libtiff | 18/12/2023 | 17/6/2026 | An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash. | |
| Modificada | Media (6.5) | 1.8% | — | LibtiffFedoraproject Fedora | 24/11/2023 | 17/6/2026 | An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB. | |
| Modificada | Media (5.5) | 0.32% | — | LibtiffRedhat Enterprise Linux | 2/11/2023 | 17/6/2026 | A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file. | |
| Modificada | Media (6.5) | 1.3% | — | LibtiffFedoraproject FedoraRedhat Enterprise Linux | 5/10/2023 | 17/6/2026 | A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. |