Known Vulnerabilities for products from Libtiff

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Libtiff".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-22844 LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 ... 5.5 - MEDIUM 2022-01-10 2022-11-16
CVE-2022-0562 Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff version... 5.5 - MEDIUM 2022-02-11 2023-11-07
CVE-2022-0561 Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versi... 5.5 - MEDIUM 2022-02-11 2023-11-07
CVE-2020-35524 A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially... 7.8 - HIGH 2021-03-09 2023-11-07
CVE-2020-35523 An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject ... 7.8 - HIGH 2021-03-09 2023-11-07
CVE-2020-35522 In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a ... 5.5 - MEDIUM 2021-03-09 2023-11-07
CVE-2020-35521 A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resu... 5.5 - MEDIUM 2021-03-09 2023-11-07
CVE-2020-18768 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.5 - MEDIUM 2023-08-22 2023-08-25
CVE-2019-17546 tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that pote... 8.8 - HIGH 2019-10-14 2023-11-07
CVE-2019-14973 _TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they ... 6.5 - MEDIUM 2019-08-14 2023-11-07
CVE-2019-7663 An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4... 6.5 - MEDIUM 2019-02-09 2020-08-24
CVE-2019-6128 The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb. 8.8 - HIGH 2019-01-11 2023-03-01
CVE-2018-19210 In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead ... 6.5 - MEDIUM 2018-11-12 2023-11-07
CVE-2018-18661 An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c... 6.5 - MEDIUM 2018-10-26 2019-08-06
CVE-2018-18557 LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0... 8.8 - HIGH 2018-10-22 2021-03-05
CVE-2018-17795 The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (h... 8.8 - HIGH 2018-09-30 2020-10-16
CVE-2018-17101 An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c... 8.8 - HIGH 2018-09-16 2019-03-21
CVE-2018-17100 An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a den... 8.8 - HIGH 2018-09-16 2019-03-21
CVE-2018-17000 A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in L... 6.5 - MEDIUM 2018-09-13 2019-04-05
CVE-2018-16335 newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a den... 8.8 - HIGH 2018-09-02 2020-08-24

Known software with vulnerabilities from Libtiff

Type Vendor Product Version
ApplicationLibtiffLibtiff-