Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 49

Количество 49

github логотип

GHSA-gvgc-3ch5-px8p

около 1 года назад

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2025-20034-0

11 месяцев назад

ELSA-2025-20034-0: libtiff security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-13919

около 1 года назад

Уязвимость функции get_histogram библиотеки LibTIFF, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-8177

около 1 года назад

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-8177

около 1 года назад

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2025-8177

около 1 года назад

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2025-8177

7 месяцев назад

LibTIFF thumbnail.c setrow buffer overflow

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-8177

около 1 года назад

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-9900

около 1 года назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-9900

около 1 года назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2025-9900

около 1 года назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2025-9900

12 месяцев назад

Libtiff: libtiff write-what-where

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-9900

около 1 года назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w743-578r-x56m

около 1 года назад

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2025-13920

около 1 года назад

Уязвимость функции setrow библиотеки LibTIFF, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3961-1

11 месяцев назад

Security update for tiff

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3941-1

11 месяцев назад

Security update for tiff

EPSS: Низкий
rocky логотип

RLSA-2025:19156

11 месяцев назад

Important: libtiff security update

EPSS: Низкий
rocky логотип

RLSA-2025:17675

12 месяцев назад

Important: compat-libtiff3 security update

EPSS: Низкий
github логотип

GHSA-qc8j-wvjf-7jfj

около 1 года назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gvgc-3ch5-px8p

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.

CVSS3: 5.3
0%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-20034-0

ELSA-2025-20034-0: libtiff security update (IMPORTANT)

0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-13919

Уязвимость функции get_histogram библиотеки LibTIFF, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.3
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-8177

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.3
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-8177

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.8
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-8177

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.3
0%
Низкий
около 1 года назад
msrc логотип
CVE-2025-8177

LibTIFF thumbnail.c setrow buffer overflow

CVSS3: 5.3
0%
Низкий
7 месяцев назад
debian логотип
CVE-2025-8177

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as ...

CVSS3: 5.3
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-9900

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
1%
Низкий
около 1 года назад
redhat логотип
CVE-2025-9900

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
1%
Низкий
около 1 года назад
nvd логотип
CVE-2025-9900

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
1%
Низкий
около 1 года назад
msrc логотип
CVE-2025-9900

Libtiff: libtiff write-what-where

CVSS3: 8.8
1%
Низкий
12 месяцев назад
debian логотип
CVE-2025-9900

A flaw was found in Libtiff. This vulnerability is a "write-what-where ...

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-w743-578r-x56m

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.3
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-13920

Уязвимость функции setrow библиотеки LibTIFF, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.3
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:3961-1

Security update for tiff

1%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:3941-1

Security update for tiff

1%
Низкий
11 месяцев назад
rocky логотип
RLSA-2025:19156

Important: libtiff security update

1%
Низкий
11 месяцев назад
rocky логотип
RLSA-2025:17675

Important: compat-libtiff3 security update

1%
Низкий
12 месяцев назад
github логотип
GHSA-qc8j-wvjf-7jfj

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
1%
Низкий
около 1 года назад

Уязвимостей на страницу