Search CVE reports


Toggle filters

111 – 120 of 278 results


CVE-2018-10126

Low priority
Needs evaluation

ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.

4 affected packages

tiff, libjpeg-turbo, libjpeg6b, libjpeg9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Not affected Not affected Not affected Not affected
libjpeg-turbo Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libjpeg6b Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libjpeg9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-8905

Low priority

Some fixes available 3 of 4

In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Not affected Fixed
Show less packages

CVE-2018-7456

Negligible priority

Some fixes available 2 of 3

A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta,...

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Not affected Not affected
Show less packages

CVE-2018-5784

Low priority
Fixed

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs...

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages

CVE-2018-5360

Low priority

Some fixes available 2 of 3

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Not affected
Show less packages

CVE-2017-18013

Negligible priority

Some fixes available 3 of 4

In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages

CVE-2017-17973

Medium priority
Ignored

In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Ignored
Show less packages

CVE-2017-17942

Low priority
Ignored

In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Not affected Not affected Not affected
Show less packages

CVE-2017-17095

Negligible priority

Some fixes available 3 of 4

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages

CVE-2017-13727

Low priority

Some fixes available 2 of 3

There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff
Show less packages