Vulnerabilities > Libtiff > Libtiff > 3.5.2

DATE CVE VULNERABILITY TITLE RISK
2006-08-03 CVE-2006-3459 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Libtiff
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arbitrary code or cause a denial of service via unspecified vectors, including a large tdir_count value in the TIFFFetchShortPair function in tif_dirread.c.
network
low complexity
libtiff adobe CWE-119
7.5
2006-06-08 CVE-2006-2193 Remote Buffer Overflow vulnerability in LibTIFF tiff2pdf
Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.
network
low complexity
libtiff
7.5
2006-04-25 CVE-2006-2026 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Libtiff
Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to "setfield/getfield methods in cleanup functions." This vulnerability is addressed in the following product release: libTIFF, libTIFF, 3.8.1
network
low complexity
libtiff CWE-119
6.5
2006-04-25 CVE-2006-2025 Integer Overflow vulnerability in LibTiff TIFFFetchData
Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted TIFF image.
network
low complexity
libtiff
6.5
2006-04-25 CVE-2006-2024 Denial of Service vulnerability in LibTiff
Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.
network
low complexity
libtiff
4.0
2005-05-14 CVE-2005-1544 Buffer Overflow vulnerability in LibTIFF TIFFOpen
Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.
network
low complexity
libtiff
7.5
2005-01-27 CVE-2004-0886 Buffer Overflow vulnerability in LibTIFF
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
5.0
2005-01-10 CVE-2004-1308 Unspecified vulnerability in Libtiff
Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.
network
low complexity
libtiff
critical
10.0
2005-01-06 CVE-2004-1183 Integer Overflow vulnerability in LibTIFF TIFFDUMP Heap Corruption
Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.
network
high complexity
libtiff
5.1
2004-12-23 CVE-2004-0803 Buffer Overflow vulnerability in LibTIFF
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
7.5