Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9535

Опубликовано: 22 нояб. 2016
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libtiff:libtiff:4.0.6:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00739
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

CVSS3: 7
redhat
почти 9 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

CVSS3: 4
msrc
20 дней назад

MITRE CVE-2016-9535: LibTIFF Heap Buffer Overflow Vulnerability

CVSS3: 9.8
debian
почти 9 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that ...

CVSS3: 9.8
github
больше 3 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

EPSS

Процентиль: 72%
0.00739
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-119