Libtiff is an image-processing library embedded across an enormous range of applications, appliances, and document-handling systems despite its narrow product scope, giving it an outsized prominence in the vulnerability landscape. The vendor's exposure concentrates entirely in the core libtiff library and recurs through memory-safety and input-validation weakness classes—including buffer-boundary violations, out-of-bounds reads and writes, and improper input validation—that reflect the library's role as a parser of untrusted TIFF image data. A moderate tendency toward public exploit availability reflects the breadth of downstream products that bundle the library and the appeal of image-parsing flaws to attackers seeking remote code execution. Defenders should inventory products that link libtiff rather than tracking the library alone, since remediation typically depends on downstream vendors rebuilding and redistributing; live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libtiff over time
Signals from CVEs in this vendor scope (262 CVEs).
262 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3459HIGH Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arb | Aug 3, 2006 | 7.5 | 72 | NO | YES |
CVE-2018-18557HIGH LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (wi | Oct 22, 2018 | 8.8 | 47 | NO | YES |
CVE-2017-17095HIGH tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have | Dec 2, 2017 | 8.8 | 44 | NO | YES |
CVE-2018-12900HIGH Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0 | Jun 26, 2018 | 8.8 | 40 | NO | NO |
CVE-2006-2025MEDIUM Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitr | Apr 25, 2006 | 6.5 | 38 | NO | YES |
CVE-2006-2026MEDIUM Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a cr | Apr 25, 2006 | 6.5 | 37 | NO | YES |
CVE-2004-1308HIGH Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TI | Jan 10, 2005 | 10.0 | 37 | NO | NO |
CVE-2006-2656HIGH Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not | May 30, 2006 | 7.5 | 36 | NO | YES |
CVE-2017-9936MEDIUM In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack. | Jun 26, 2017 | 6.5 | 35 | NO | YES |
CVE-2017-9147MEDIUM LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file. | May 22, 2017 | 6.5 | 35 | NO | YES |
Signals from CVEs in this vendor scope (262 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libtiff.
Media articles that mention a CVE ID that affects a product developed by Libtiff — matched by CVE ID, not by vendor name.