Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libtiff

First CVE: Nov 3, 2004Active for: 22 yearsTotal CVEs: 262
46.4
VTI Score
High

Libtiff is an image-processing library embedded across an enormous range of applications, appliances, and document-handling systems despite its narrow product scope, giving it an outsized prominence in the vulnerability landscape. The vendor's exposure concentrates entirely in the core libtiff library and recurs through memory-safety and input-validation weakness classes—including buffer-boundary violations, out-of-bounds reads and writes, and improper input validation—that reflect the library's role as a parser of untrusted TIFF image data. A moderate tendency toward public exploit availability reflects the breadth of downstream products that bundle the library and the appeal of image-parsing flaws to attackers seeking remote code execution. Defenders should inventory products that link libtiff rather than tracking the library alone, since remediation typically depends on downstream vendors rebuilding and redistributing; live severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
262
Total CVEs
More Total CVEs than 100% of tracked vendors
11.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libtiff over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2004
21 years ago
Most Recent CVE
Mar 24, 2026
122 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (262 CVEs).

262 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-3459HIGH
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arb
Aug 3, 20067.572NOYES
CVE-2018-18557HIGH
LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (wi
Oct 22, 20188.847NOYES
CVE-2017-17095HIGH
tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have
Dec 2, 20178.844NOYES
CVE-2018-12900HIGH
Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0
Jun 26, 20188.840NONO
CVE-2006-2025MEDIUM
Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitr
Apr 25, 20066.538NOYES
CVE-2006-2026MEDIUM
Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a cr
Apr 25, 20066.537NOYES
CVE-2004-1308HIGH
Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TI
Jan 10, 200510.037NONO
CVE-2006-2656HIGH
Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not
May 30, 20067.536NOYES
CVE-2017-9936MEDIUM
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
Jun 26, 20176.535NOYES
CVE-2017-9147MEDIUM
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
May 22, 20176.535NOYES
View all 262 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products262 CVEs
60%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local97 (37.0%)
Network111 (42.4%)
Unknown54 (20.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low202 (77.1%)
High6 (2.3%)
Unknown54 (20.6%)
User Interaction
None41 (15.6%)
Unknown54 (20.6%)
Required167 (63.7%)
Privileges Required
Low11 (4.2%)
High0 (0.0%)
None197 (75.2%)
Unknown54 (20.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (262 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.4% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
16 CVEs
6.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libtiff.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libtiff — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libtiff's Products

View all 8 CNAs →

Top CWEs