Логотип exploitDog
bind: "CVE-2025-9165"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-9165"

Количество 11

Количество 11

ubuntu логотип

CVE-2025-9165

3 месяца назад

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because "this is a memory leak on a command line tool that is about to exit anyway". In the reply the project maintainer declares this issue as "a simple 'bug' when leaving the command line tool and (...) not a security issue at all".

CVSS3: 2.5
EPSS: Низкий
redhat логотип

CVE-2025-9165

3 месяца назад

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2025-9165

3 месяца назад

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because "this is a memory leak on a command line tool that is about to exit anyway". In the reply the project maintainer declares this issue as "a simple 'bug' when leaving the command line tool and (...) not a security issue at all".

CVSS3: 2.5
EPSS: Низкий
msrc логотип

CVE-2025-9165

2 месяца назад

LibTIFF tiffcmp tiffcmp.c InitCCITTFax3 memory leak

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2025-9165

3 месяца назад

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIF ...

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-64vg-6m9q-6vr3

3 месяца назад

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue.

CVSS3: 3.3
EPSS: Низкий
fstec логотип

BDU:2025-12470

3 месяца назад

Уязвимость компонента tiffcmp библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03346-1

около 1 месяца назад

Security update for tiff

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03345-1

около 1 месяца назад

Security update for tiff

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03348-1

около 1 месяца назад

Security update for tiff

EPSS: Низкий
redos логотип

ROS-20251105-02

3 дня назад

Множественные уязвимости libtiff

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-9165

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because "this is a memory leak on a command line tool that is about to exit anyway". In the reply the project maintainer declares this issue as "a simple 'bug' when leaving the command line tool and (...) not a security issue at all".

CVSS3: 2.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-9165

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue.

CVSS3: 3.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-9165

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because "this is a memory leak on a command line tool that is about to exit anyway". In the reply the project maintainer declares this issue as "a simple 'bug' when leaving the command line tool and (...) not a security issue at all".

CVSS3: 2.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-9165

LibTIFF tiffcmp tiffcmp.c InitCCITTFax3 memory leak

CVSS3: 5.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-9165

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIF ...

CVSS3: 2.5
0%
Низкий
3 месяца назад
github логотип
GHSA-64vg-6m9q-6vr3

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue.

CVSS3: 3.3
0%
Низкий
3 месяца назад
fstec логотип
BDU:2025-12470

Уязвимость компонента tiffcmp библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.3
0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03346-1

Security update for tiff

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03345-1

Security update for tiff

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03348-1

Security update for tiff

около 1 месяца назад
redos логотип
ROS-20251105-02

Множественные уязвимости libtiff

CVSS3: 8.8
3 дня назад

Уязвимостей на страницу