Known vulnerabilities in libtiff (Red Hat package)
Vendor:
Red Hat Inc.
Software:
libtiff (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:libtiff_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
75
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
4.4.0-12.el9_4.6
4.4.0-8.el9_2.6
4.0.9-29.el8_8.3
4.0.9-21.el8_6.3
4.6.0-6.el10_0.4
4.0.9-38.el8_10
4.4.0-18.el9_8.1
4.6.0-8.el10_2.4
4.0.3-35.el7_9.2
4.4.0-12.el9_4.5
4.0.9-18.el8_4.2
4.4.0-8.el9_2.5
4.4.0-13.el9_6.4
4.2.0-3.el9_0.3
4.0.9-29.el8_8.2
4.0.9-37.el8_10
4.4.0-15.el9_7.3
4.6.0-6.el10_1.3
4.6.0-6.el10_0.2
4.6.0-6.el10_1.2
4.4.0-13.el9_6.3
4.4.0-8.el9_2.4
4.4.0-12.el9_4.4
4.2.0-3.el9_0.2
4.0.3-35.el7_9.1
4.0.9-17.el8_2.1
4.0.9-18.el8_4.1
4.0.9-21.el8_6.1
4.4.0-15.el9_7.2
4.0.9-36.el8_10
4.0.9-29.el8_8.1
4.0.9-35.el8_10
4.6.0-6.el10_0.1
4.4.0-13.el9_6.2
4.0.9-34.el8_10
4.4.0-12.el9_4.1
3.5.7-22.el3
4.0.9-33.el8_10
4.4.0-8.el9_2.1
4.0.9-32.el8_10
3.9.4-1.el6_0.3
3.6.1-12.el4_8.5
3.8.2-7.el5_5.5
3.6.1-12.el4_8.4
3.8.2-7.el5_3.4
3.6.1-12.el4_7.2
3.8.2-7.el5_2.2
4.0.9-31.el8
4.4.0-12.el9
4.4.0-10.el9
4.0.9-29.el8_8
4.0.9-28.el8_8
4.4.0-8.el9_2
4.0.9-27.el8
4.4.0-7.el9
4.0.9-21.el8
4.0.9-20.el8
4.4.0-5.el9_1
4.0.9-26.el8_7
4.4.0-2.el9
4.0.9-23.el8
4.0.9-18.el8
4.0.3-35.el7
4.0.9-17.el8
4.0.9-15.el8
4.0.3-32.el7
3.5.7-31.el2
3.5.7-31.el3
3.5.7-34.el3
3.6.1-17.el4
3.6.1-18.el4
3.8.2-14.el5_8
3.8.2-15.el5_8
3.8.2-18.el5_8
3.8.2-19.el5_10
4.0.3-25.el7_2
4.0.3-27.el7_3
3.9.4-21.el6_8
3.9.4-18.el6_8
3.9.4-10.el6_5
3.9.4-9.el6_3
3.9.4-6.el6_3
3.9.4-5.el6_2
3.9.4-1.el6_0
3.9.4-1.el6
Vulnerabilities (75)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU132310 - Integer overflow CVE-2026-4775 |
CWE-190 | Medium | 4.0.3-35.el7_9.2, 4.0.9-18.el8_4.2, 4.0.9-29.el8_8.2, 4.0.9-37.el8_10, 4.2.0-3.el9_0.3, 4.4.0-8.el9_2.5, 4.4.0-12.el9_4.5, 4.4.0-13.el9_6.4, 4.4.0-15.el9_7.3, 4.6.0-6.el10_1.3 | 26.05.2026 |
SB2026052646 SB2026052647 SB2026052648 and 21 more |
||
| #VU116196 - Memory corruption CVE-2025-9900 |
CWE-119 | High | 4.0.3-35.el7_9.1, 4.0.9-17.el8_2.1, 4.0.9-18.el8_4.1, 4.0.9-21.el8_6.1, 4.0.9-29.el8_8.1, 4.0.9-35.el8_10, 4.2.0-3.el9_0.2, 4.4.0-8.el9_2.4, 4.4.0-12.el9_4.4, 4.4.0-13.el9_6.2, 4.4.0-15.el9_7.2, 4.6.0-6.el10_0.1 | 30.09.2025 |
SB2025093033 SB2025093035 SB2025100921 and 50 more |
||
| #VU113649 - Use After Free CVE-2025-8176 |
CWE-416 | High | 4.0.3-35.el7_9.1, 4.0.9-36.el8_10, 4.4.0-8.el9_2.4, 4.4.0-12.el9_4.4, 4.4.0-13.el9_6.2, 4.4.0-15.el9_7.2 | 05.08.2025 |
SB2025080553 SB2025080555 SB2025081259 and 21 more |
||
| #VU113646 - Memory corruption CVE-2025-8177 |
CWE-119 | High | 4.0.3-35.el7_9.1 | 05.08.2025 |
SB2025080553 SB2025080554 SB2025080555 and 10 more |
||
| #VU96001 - NULL Pointer Dereference CVE-2024-7006 |
CWE-476 | Medium | 4.0.9-33.el8_10, 4.4.0-8.el9_2.1, 4.4.0-12.el9_4.1 | 14.08.2024 |
SB2024081444 SB2024081449 SB2024081450 and 30 more |
||
| #VU86757 - Heap-based Buffer Overflow CVE-2023-6228 |
CWE-122 | High | 4.0.9-32.el8_10, 4.4.0-12.el9 | 23.02.2024 |
SB2024022317 SB2024022331 SB2024022771 and 22 more |
||
| #VU86755 - Out-of-bounds write CVE-2023-52356 |
CWE-787 | High | 4.0.9-32.el8_10, 4.4.0-13.el9_6.3, 4.6.0-6.el10_0.2, 4.6.0-6.el10_1.2 | 23.02.2024 |
SB2024022315 SB2024022316 SB2024022317 and 35 more |
||
| #VU83511 - Integer overflow CVE-2023-40745 |
CWE-190 | High | 4.4.0-12.el9 | 27.11.2023 |
SB2023112765 SB2023112802 SB2023121108 and 13 more |
||
| #VU83502 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-40090 |
CWE-835 | Medium | 4.4.0-12.el9 | 27.11.2023 |
SB2023112716 SB2023112717 SB2023121257 and 12 more |
||
| #VU81692 - Integer overflow CVE-2023-41175 |
CWE-190 | High | 4.4.0-12.el9 | 08.10.2023 |
SB2023100807 SB2023100809 SB2023112802 and 14 more |
||
| #VU79568 - NULL Pointer Dereference CVE-2023-2731 |
CWE-476 | Medium | 4.4.0-10.el9 | 16.08.2023 |
SB2023081605 SB2023081622 SB2023082320 and 13 more |
||
| #VU79327 - Buffer overflow CVE-2023-3618 |
CWE-120 | Medium | 4.4.0-12.el9 | 10.08.2023 |
SB2023081007 SB2023081622 SB2023101985 and 17 more |
||
| #VU78727 - Missing release of memory after effective lifetime CVE-2023-3576 |
CWE-401 | Medium | 4.4.0-10.el9 | 27.07.2023 |
SB2023071613 SB2023072759 SB2023073122 and 14 more |
||
| #VU78288 - NULL Pointer Dereference CVE-2023-3316 |
CWE-476 | Medium | 4.4.0-10.el9 | 16.07.2023 |
SB2023071613 SB2023071619 SB2023081007 and 17 more |
||
| #VU78287 - Memory corruption CVE-2023-26966 |
CWE-119 | High | 4.4.0-10.el9 | 16.07.2023 |
SB2023071613 SB2023071619 SB2023081007 and 14 more |
||
| #VU78286 - Heap-based Buffer Overflow CVE-2023-26965 |
CWE-122 | High | 4.4.0-10.el9 | 16.07.2023 |
SB2023071613 SB2023071619 SB2023081007 and 16 more |
||
| #VU78285 - Memory corruption CVE-2023-25433 |
CWE-119 | Medium | 4.0.9-32.el8_10 | 16.07.2023 |
SB2023071613 SB2023071619 SB2023081007 and 17 more |
||
| #VU71620 - Heap-based Buffer Overflow CVE-2022-48281 |
CWE-122 | High | 4.0.9-28.el8_8, 4.4.0-8.el9_2 | 30.01.2023 |
SB2023013012 SB2023013014 SB2023013015 and 27 more |
||
| #VU16203 - Heap-based Buffer Overflow CVE-2018-15209 |
CWE-122 | Low | 4.0.9-32.el8_10 | 03.12.2018 |
SB2018120304 SB2018102427 SB2018102428 and 11 more |
||
| #VU11496 - Heap-based Buffer Overflow CVE-2017-17095 |
CWE-122 | Low | 4.0.9-34.el8_10 | 03.04.2018 |
SB2018011917 SB2018120304 SB2020031510 and 11 more |
Showing elements 1 - 20 out of 75