Libtiff Vulnerabilities
Comprehensive security vulnerability database for Libtiff products
6
1
3
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2025-61145 | 5.0 | This vulnerability allows an attacker to potentially crash the libtiff software or execute arbitrary code by exploiting a flaw in the tiffcrop tool, which can happen if the attacker can manipulate the input files processed by this tool. To take advantage of this issue, the attacker needs to provide specially crafted TIFF files to the application using libtiff, which could be done through file uploads or other means of file handling. | libtifflibtiff | Theoretical | about 1 month agoFeb 23, 2026 |
| CVE-2025-61144 | 7.3 | This vulnerability allows an attacker to execute malicious code on a system by exploiting a stack overflow in the libtiff library when processing specially crafted TIFF images. To be successful, the attacker needs to convince the victim to open a manipulated TIFF file, which could lead to unauthorized access or control over the affected system. | libtifflibtiff | Theoretical | about 1 month agoFeb 23, 2026 |
| CVE-2025-61143 | 5.5 | This vulnerability allows an attacker to crash applications that use the libtiff library by exploiting a flaw in how the library handles certain image files, leading to a program failure. To take advantage of this, the attacker must be able to provide a specially crafted TIFF file to the application. | libtifflibtiff | Theoretical | about 1 month agoFeb 23, 2026 |
| CVE-2023-52356 | 7.5 | An attacker can exploit a flaw in libtiff to crash applications by sending a specially crafted TIFF file, which can lead to a denial of service. This vulnerability occurs when the TIFFReadRGBATileExt() function processes the malicious file, causing the program to fail unexpectedly. | libtifflibtiff | Exploit Available | about 2 years agoJan 25, 2024 |
| CVE-2023-52355 | 7.5 | This vulnerability allows an attacker to crash applications that use the libtiff library by sending them a specially crafted TIFF file, which can be as small as 379 KB. To exploit this flaw, the attacker needs to get the target to open the malicious TIFF file, leading to a denial of service. | libtifflibtiff | Exploit Available | about 2 years agoJan 25, 2024 |
| CVE-2017-5225 | 9.8 | This vulnerability allows an attacker to potentially run malicious code on a system or crash it by tricking the libtiff tool into processing a specially crafted image file with a manipulated BitsPerSample value. The attacker needs to have access to a vulnerable version of the libtiff tool to exploit this weakness. | libtifflibtiff | Exploit Available | about 9 years agoJan 12, 2017 |
About Libtiff Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Libtiff products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.