Search CVE reports


Toggle filters

111 – 120 of 276 results


CVE-2018-10779

Low priority

Some fixes available 4 of 5

TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed
Show less packages

CVE-2018-10126

Low priority
Needs evaluation

ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.

4 affected packages

tiff, libjpeg-turbo, libjpeg6b, libjpeg9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Not affected Not affected Not affected Not affected
libjpeg-turbo Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libjpeg6b Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libjpeg9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2017-9936

Medium priority

Some fixes available 2 of 4

In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages

CVE-2017-9935

Medium priority

Some fixes available 3 of 5

In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bounds read...

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages

CVE-2017-9815

Low priority

Some fixes available 2 of 4

In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function _TIFFmalloc in tif_unix.c) via...

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages

CVE-2017-9404

Low priority

Some fixes available 2 of 4

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages

CVE-2017-9403

Low priority

Some fixes available 2 of 4

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages

CVE-2017-9147

Negligible priority

Some fixes available 1 of 3

LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages

CVE-2017-9117

Low priority

Some fixes available 2 of 4

In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read...

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages

CVE-2017-7602

Medium priority

Some fixes available 2 of 5

LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages