Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-9535

34
FAUCET Score

CVE-2016-9535 is a critical vulnerability in libtiff versions 4.0.6 and earlier, specifically within the tif_predict.h and tif_predict.c files. This flaw can lead to assertion failures in debug mode or, more critically, heap-buffer-overflows in release mode when processing specially crafted TIFF files with unusual tile sizes, particularly those using YCbCr with subsampling. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk, allowing unauthenticated attackers to achieve full compromise (confidentiality, integrity, and availability) over a network with low attack complexity. While there is no known active exploitation in the wild, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion with 12 mentions and media coverage, indicating awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
4.0.6CPE matchmatch criteria
cpe:2.3:a:libtiff:libtiff:4.0.6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
4.77%
Probability of exploitation in next 30 days
EPSS Percentile
91.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0477 is in the 85th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (45)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 R2 (Server Core installation)Fixed in: 6.3.9600.22824
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Fixed in: 6.1.7601.27974
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012Fixed in: 6.2.9200.25722
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 (Server Core installation)Fixed in: 6.2.9200.25722
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 R2Fixed in: 6.3.9600.22824
View patch
microsoftpatch availablevia msrc
Product: Microsoft Office for AndroidFixed in: 16.0.19426.20044
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for 32-bit SystemsFixed in: 10.0.17763.7919
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for x64-based SystemsFixed in: 10.0.17763.7919
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019Fixed in: 10.0.17763.7919
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019 (Server Core installation)Fixed in: 10.0.17763.7919
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022Fixed in: 10.0.20348.4294
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022 (Server Core installation)Fixed in: 10.0.20348.4294
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for 32-bit SystemsFixed in: 10.0.19044.6456
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for ARM64-based SystemsFixed in: 10.0.19044.6456
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for x64-based SystemsFixed in: 10.0.19044.6456
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 22H2 for ARM64-based SystemsFixed in: 10.0.22621.6060
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 22H2 for x64-based SystemsFixed in: 10.0.22621.6060
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for x64-based SystemsFixed in: 10.0.19045.6456
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for ARM64-based SystemsFixed in: 10.0.19045.6456
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for 32-bit SystemsFixed in: 10.0.19045.6456
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2025 (Server Core installation)Fixed in: 10.0.26100.6899
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 24H2 for ARM64-based SystemsFixed in: 10.0.26100.6899
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 24H2 for x64-based SystemsFixed in: 10.0.26100.6899
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2025Fixed in: 10.0.26100.6899
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 25H2 for ARM64-based SystemsFixed in: 10.0.26200.6899
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 25H2 for x64-based SystemsFixed in: 10.0.26200.6899
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 23H2 for ARM64-based SystemsFixed in: 10.0.22631.6060
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 23H2 for x64-based SystemsFixed in: 10.0.22631.6060
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022, 23H2 Edition (Server Core installation)Fixed in: 10.0.25398.1913
View patch
microsoftpatch availablevia msrc
Product: Windows 10 for 32-bit SystemsFixed in: 10.0.10240.21161
View patch
microsoftpatch availablevia msrc
Product: Windows 10 for x64-based SystemsFixed in: 10.0.10240.21161
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1607 for 32-bit SystemsFixed in: 10.0.14393.8519
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1607 for x64-based SystemsFixed in: 10.0.14393.8519
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016Fixed in: 10.0.14393.8519
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016 (Server Core installation)Fixed in: 10.0.14393.8519
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)Fixed in: 6.0.6003.23571
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for 32-bit Systems Service Pack 2Fixed in: 6.0.6003.23571
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)Fixed in: 6.0.6003.23571
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for x64-based Systems Service Pack 2Fixed in: 6.0.6003.23571
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 R2 for x64-based Systems Service Pack 1Fixed in: 6.1.7601.27974
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libtiff-0:4.0.3-27.el7_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: libtiff-0:3.9.4-21.el6_8
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: libtiff
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: compat-libtiff3

Vendor Advisories (2)

microsoft2025-Oct/CVE-2016-9535Critical

MITRE CVE-2016-9535: LibTIFF Heap Buffer Overflow Vulnerability

Oct 14, 2025
redhatCVE-2016-9535Moderate

libtiff: Predictor heap-buffer-overflow

Nov 4, 2016

References

rhn.redhat.com / errata/RHSA-2017-0225.html
github.com / vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1
Issue TrackingPatchThird Party Advisory
github.com / vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33
Issue TrackingPatchThird Party Advisory
debian.org / security/2017/dsa-3844
securityfocus.com / bid/94484
Third Party AdvisoryVDB Entry
securityfocus.com / bid/94744