Vulnerabilities > Libtiff > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-04-11 CVE-2016-5322 Out-of-bounds Read vulnerability in multiple products
The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
local
low complexity
libtiff debian CWE-125
5.5
2017-04-09 CVE-2017-7595 Divide By Zero vulnerability in Libtiff 4.0.7
The JPEGSetupEncode function in tiff_jpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.
local
low complexity
libtiff CWE-369
5.5
2017-04-09 CVE-2017-7594 Missing Release of Resource after Effective Lifetime vulnerability in Libtiff 4.0.7
The OJPEGReadHeaderInfoSecTablesDcTable function in tif_ojpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (memory leak) via a crafted image.
local
low complexity
libtiff CWE-772
5.5
2017-04-09 CVE-2017-7593 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libtiff 4.0.7
tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.
local
low complexity
libtiff CWE-119
5.5
2017-03-24 CVE-2016-10267 Divide By Zero vulnerability in Libtiff 4.0.7
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8.
local
low complexity
libtiff CWE-369
5.5
2017-03-24 CVE-2016-10266 Divide By Zero vulnerability in Libtiff 4.0.7
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_read.c:351:22.
local
low complexity
libtiff CWE-369
5.5
2017-03-17 CVE-2015-7313 Resource Management Errors vulnerability in Libtiff
LibTIFF allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
local
low complexity
libtiff CWE-399
5.5
2017-03-07 CVE-2016-5315 Out-of-bounds Read vulnerability in multiple products
The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
local
low complexity
libtiff debian CWE-125
5.5
2017-03-01 CVE-2016-10095 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libtiff 4.0.7
Stack-based buffer overflow in the _TIFFVGetField function in tif_dir.c in LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7 and 4.0.8 allows remote attackers to cause a denial of service (crash) via a crafted TIFF file.
local
low complexity
libtiff CWE-119
5.5
2017-02-06 CVE-2016-9532 Out-of-bounds Read vulnerability in multiple products
Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.
local
low complexity
libtiff debian CWE-125
5.5