Vulnerabilidades en libtiff
34 resultadosAnálisis Vexday
A libtiff acumula 32 vulnerabilidades históricas na base Vexday, nenhuma delas atualmente sob exploração ativa (KEV). A fraqueza dominante é buffer overflow (CWE-787), padrão em bibliotecas legadas de processamento de imagem. Sem publicações recentes e sem críticas ativas, o risco presente é baixo, mas a manutenção de patches anteriores permanece essencial dada a natureza do código e sua presença em cadeia de suprimento.
CVE-2022-3626MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections, tools/tiffcrop.c:7EPSS 1.0%CVE-2022-2953MEDIUMLibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service viaEPSS 0.6%CVE-2022-3570HIGHMultiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memEPSS 0.5%CVE-2023-0800MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a craftedEPSS 0.4%CVE-2023-0802MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724, allowing attackers to cause a denial-of-service via a craftedEPSS 0.4%CVE-2023-0804MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a craftedEPSS 0.4%CVE-2023-0801MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, EPSS 0.4%CVE-2023-0803MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-service via a craftedEPSS 0.4%CVE-2023-0799MEDIUMLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-service via a crafted EPSS 0.4%CVE-2022-4645MEDIUMLibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff EPSS 0.4%CVE-2023-0797MEDIUMLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6921, aEPSS 0.4%CVE-2023-0798MEDIUMLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3400, allowing attackers to cause a denial-of-service via a crafted EPSS 0.4%CVE-2023-0796MEDIUMLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3592, allowing attackers to cause a denial-of-service via a crafted EPSS 0.4%CVE-2023-0795MEDIUMLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3488, allowing attackers to cause a denial-of-service via a crafted EPSS 0.4%