{"schema_version":1,"title":"LibTIFF vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 20 vulnerabilities in LibTIFF: 0 in the last 7 days and 5 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-18495, was published on 11 September 2026.","url":"https://junglewise.ai/threats/technologies/libtiff","json_url":"https://junglewise.ai/threats/technologies/libtiff.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/libtiff","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":11,"all_time":20,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":5,"last_365_days":6},"latest":[{"cve":"CVE-2026-18495","cvss":6.1,"epss":0.0012,"slug":"cve-2026-18495-libtiff-heap-buffer-overflow-in-tiff2pdf","title":"libtiff heap buffer overflow in tiff2pdf","severity":"medium","exploited":false,"published_at":"2026-09-11T18:16:56.69+00:00","url":"https://junglewise.ai/threats/cve-2026-18495-libtiff-heap-buffer-overflow-in-tiff2pdf"},{"cve":"CVE-2026-52491","cvss":8.4,"epss":0.0019,"slug":"cve-2026-52491-libtiff-integer-overflow-in-thumbnail-buffer-allocation","title":"libtiff integer overflow in thumbnail buffer allocation","severity":"high","exploited":false,"published_at":"2026-08-25T21:17:01.467+00:00","url":"https://junglewise.ai/threats/cve-2026-52491-libtiff-integer-overflow-in-thumbnail-buffer-allocation"},{"cve":"CVE-2026-52492","cvss":7.8,"epss":0.0019,"slug":"cve-2026-52492-libtiff-integer-overflow-in-rgb2ycbcr-cvtraster","title":"libtiff integer overflow in rgb2ycbcr cvtRaster","severity":"high","exploited":false,"published_at":"2026-08-24T21:17:19.927+00:00","url":"https://junglewise.ai/threats/cve-2026-52492-libtiff-integer-overflow-in-rgb2ycbcr-cvtraster"},{"cve":"CVE-2026-52490","cvss":9.8,"epss":0.0051,"slug":"cve-2026-52490-libtiff-integer-overflow-in-tiffcrop-s-option","title":"libtiff integer overflow in tiffcrop -S option","severity":"critical","exploited":false,"published_at":"2026-08-24T21:17:19.803+00:00","url":"https://junglewise.ai/threats/cve-2026-52490-libtiff-integer-overflow-in-tiffcrop-s-option"},{"cve":"CVE-2026-12912","cvss":7.3,"slug":"cve-2026-12912-libtiff-heap-overflow-in-pixarlogdecode-with-8bitabgr-format","title":"libtiff heap overflow in PixarLogDecode with 8BITABGR format","severity":"high","exploited":false,"published_at":"2026-06-29T17:16:28.23+00:00","url":"https://junglewise.ai/threats/cve-2026-12912-libtiff-heap-overflow-in-pixarlogdecode-with-8bitabgr-format"},{"cve":"CVE-2026-4775","cvss":7.8,"epss":0.0005,"slug":"cve-2026-4775-libtiff-signed-integer-overflow-in-putcontig8bitycbcr44tile","title":"libtiff signed integer overflow in putcontig8bitYCbCr44tile","severity":"high","exploited":false,"published_at":"2026-03-24T15:16:39.693+00:00","url":"https://junglewise.ai/threats/cve-2026-4775-libtiff-signed-integer-overflow-in-putcontig8bitycbcr44tile"},{"cve":"CVE-2025-9900","cvss":8.8,"epss":0.0074,"slug":"cve-2025-9900-libtiff-write-what-where-condition-in-tiff-image-processing","title":"Libtiff write-what-where condition in TIFF image processing","severity":"high","exploited":false,"published_at":"2025-09-23T17:15:38.357+00:00","url":"https://junglewise.ai/threats/cve-2025-9900-libtiff-write-what-where-condition-in-tiff-image-processing"},{"cve":"CVE-2023-52356","cvss":7.5,"slug":"cve-2023-52356-libtiff-heap-buffer-overflow-in-tiffreadrgbatileext","title":"libtiff heap buffer overflow in TIFFReadRGBATileExt","severity":"high","exploited":false,"published_at":"2024-01-25T20:15:39.063+00:00","url":"https://junglewise.ai/threats/cve-2023-52356-libtiff-heap-buffer-overflow-in-tiffreadrgbatileext"},{"cve":"CVE-2016-9453","cvss":7.8,"slug":"cve-2016-9453-libtiff-out-of-bounds-write-in-tiff2pdf","title":"LibTIFF out-of-bounds write in tiff2pdf","severity":"high","exploited":false,"published_at":"2017-01-27T17:59:00.337+00:00","url":"https://junglewise.ai/threats/cve-2016-9453-libtiff-out-of-bounds-write-in-tiff2pdf"},{"cve":"CVE-2016-9448","cvss":7.5,"slug":"cve-2016-9448-libtiff-null-pointer-dereference-in-tifffetchnormaltag","title":"LibTiff NULL pointer dereference in TIFFFetchNormalTag","severity":"high","exploited":false,"published_at":"2017-01-27T17:59:00.29+00:00","url":"https://junglewise.ai/threats/cve-2016-9448-libtiff-null-pointer-dereference-in-tifffetchnormaltag"},{"cve":"CVE-2016-6223","cvss":9.1,"slug":"cve-2016-6223-libtiff-out-of-bounds-read-in-tif-read-c","title":"libtiff out-of-bounds read in tif_read.c","severity":"critical","exploited":false,"published_at":"2017-01-23T21:59:01.97+00:00","url":"https://junglewise.ai/threats/cve-2016-6223-libtiff-out-of-bounds-read-in-tif-read-c"},{"cve":"CVE-2017-5563","cvss":8.8,"slug":"cve-2017-5563-libtiff-heap-buffer-over-read-in-tif-lzw-c-via-bmp2tiff","title":"LibTIFF heap buffer over-read in tif_lzw.c via bmp2tiff","severity":"high","exploited":false,"published_at":"2017-01-23T07:59:00.69+00:00","url":"https://junglewise.ai/threats/cve-2017-5563-libtiff-heap-buffer-over-read-in-tif-lzw-c-via-bmp2tiff"},{"cve":"CVE-2016-5323","cvss":7.5,"slug":"cve-2016-5323-libtiff-divide-by-zero-in-tifffax3fillruns","title":"LibTIFF divide by zero in _TIFFFax3fillruns","severity":"high","exploited":false,"published_at":"2017-01-20T15:59:00.52+00:00","url":"https://junglewise.ai/threats/cve-2016-5323-libtiff-divide-by-zero-in-tifffax3fillruns"},{"cve":"CVE-2016-5321","cvss":6.5,"slug":"cve-2016-5321-libtiff-denial-of-service-in-dumpmodedecode","title":"LibTIFF denial of service in DumpModeDecode","severity":"medium","exploited":false,"published_at":"2017-01-20T15:59:00.49+00:00","url":"https://junglewise.ai/threats/cve-2016-5321-libtiff-denial-of-service-in-dumpmodedecode"},{"cve":"CVE-2016-5319","cvss":6.5,"slug":"cve-2016-5319-libtiff-heap-buffer-overflow-in-tif-packbits-c","title":"LibTIFF heap buffer overflow in tif_packbits.c","severity":"medium","exploited":false,"published_at":"2017-01-20T15:59:00.443+00:00","url":"https://junglewise.ai/threats/cve-2016-5319-libtiff-heap-buffer-overflow-in-tif-packbits-c"},{"cve":"CVE-2016-5318","cvss":6.5,"slug":"cve-2016-5318-libtiff-stack-buffer-overflow-in-tiffvgetfield","title":"libtiff stack buffer overflow in _TIFFVGetField","severity":"medium","exploited":false,"published_at":"2017-01-20T15:59:00.397+00:00","url":"https://junglewise.ai/threats/cve-2016-5318-libtiff-stack-buffer-overflow-in-tiffvgetfield"},{"cve":"CVE-2016-5317","cvss":6.5,"slug":"cve-2016-5317-libtiff-pixarlogdecode-buffer-overflow-in-libtiff-so","title":"libtiff PixarLogDecode buffer overflow in libtiff.so","severity":"medium","exploited":false,"published_at":"2017-01-20T15:59:00.347+00:00","url":"https://junglewise.ai/threats/cve-2016-5317-libtiff-pixarlogdecode-buffer-overflow-in-libtiff-so"},{"cve":"CVE-2016-5316","cvss":6.5,"slug":"cve-2016-5316-libtiff-out-of-bounds-read-in-pixarlogcleanup","title":"Libtiff out-of-bounds read in PixarLogCleanup","severity":"medium","exploited":false,"published_at":"2017-01-20T15:59:00.3+00:00","url":"https://junglewise.ai/threats/cve-2016-5316-libtiff-out-of-bounds-read-in-pixarlogcleanup"},{"cve":"CVE-2016-9297","cvss":7.5,"slug":"cve-2016-9297-libtiff-out-of-bounds-read-in-tifffetchnormaltag","title":"LibTiff out-of-bounds read in TIFFFetchNormalTag","severity":"high","exploited":false,"published_at":"2017-01-18T17:59:01.293+00:00","url":"https://junglewise.ai/threats/cve-2016-9297-libtiff-out-of-bounds-read-in-tifffetchnormaltag"},{"cve":"CVE-2016-9273","cvss":5.5,"slug":"cve-2016-9273-libtiff-libtiff-out-of-bounds-read-in-tiffsplit","title":"Libtiff libtiff out-of-bounds read in tiffsplit","severity":"medium","exploited":false,"published_at":"2017-01-18T17:59:01.183+00:00","url":"https://junglewise.ai/threats/cve-2016-9273-libtiff-libtiff-out-of-bounds-read-in-tiffsplit"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"LibTIFF","slug":"libtiff","vendor":{"name":"Libtiff","slug":"libtiff","url":"https://junglewise.ai/threats/vendors/libtiff"},"aliases":[],"category":"library","homepage":"http://libtiff.maptools.org/","repo_url":"https://gitlab.com/libtiff/libtiff","description":"LibTIFF is a library for reading and writing Tagged Image File Format (TIFF) files.","url":"https://junglewise.ai/threats/technologies/libtiff"},"most_severe":[{"cve":"CVE-2026-52490","cvss":9.8,"epss":0.0051,"slug":"cve-2026-52490-libtiff-integer-overflow-in-tiffcrop-s-option","title":"libtiff integer overflow in tiffcrop -S option","severity":"critical","exploited":false,"published_at":"2026-08-24T21:17:19.803+00:00","url":"https://junglewise.ai/threats/cve-2026-52490-libtiff-integer-overflow-in-tiffcrop-s-option"},{"cve":"CVE-2016-6223","cvss":9.1,"slug":"cve-2016-6223-libtiff-out-of-bounds-read-in-tif-read-c","title":"libtiff out-of-bounds read in tif_read.c","severity":"critical","exploited":false,"published_at":"2017-01-23T21:59:01.97+00:00","url":"https://junglewise.ai/threats/cve-2016-6223-libtiff-out-of-bounds-read-in-tif-read-c"},{"cve":"CVE-2025-9900","cvss":8.8,"epss":0.0074,"slug":"cve-2025-9900-libtiff-write-what-where-condition-in-tiff-image-processing","title":"Libtiff write-what-where condition in TIFF image processing","severity":"high","exploited":false,"published_at":"2025-09-23T17:15:38.357+00:00","url":"https://junglewise.ai/threats/cve-2025-9900-libtiff-write-what-where-condition-in-tiff-image-processing"},{"cve":"CVE-2017-5563","cvss":8.8,"slug":"cve-2017-5563-libtiff-heap-buffer-over-read-in-tif-lzw-c-via-bmp2tiff","title":"LibTIFF heap buffer over-read in tif_lzw.c via bmp2tiff","severity":"high","exploited":false,"published_at":"2017-01-23T07:59:00.69+00:00","url":"https://junglewise.ai/threats/cve-2017-5563-libtiff-heap-buffer-over-read-in-tif-lzw-c-via-bmp2tiff"},{"cve":"CVE-2026-52491","cvss":8.4,"epss":0.0019,"slug":"cve-2026-52491-libtiff-integer-overflow-in-thumbnail-buffer-allocation","title":"libtiff integer overflow in thumbnail buffer allocation","severity":"high","exploited":false,"published_at":"2026-08-25T21:17:01.467+00:00","url":"https://junglewise.ai/threats/cve-2026-52491-libtiff-integer-overflow-in-thumbnail-buffer-allocation"},{"cve":"CVE-2026-52492","cvss":7.8,"epss":0.0019,"slug":"cve-2026-52492-libtiff-integer-overflow-in-rgb2ycbcr-cvtraster","title":"libtiff integer overflow in rgb2ycbcr cvtRaster","severity":"high","exploited":false,"published_at":"2026-08-24T21:17:19.927+00:00","url":"https://junglewise.ai/threats/cve-2026-52492-libtiff-integer-overflow-in-rgb2ycbcr-cvtraster"},{"cve":"CVE-2026-4775","cvss":7.8,"epss":0.0005,"slug":"cve-2026-4775-libtiff-signed-integer-overflow-in-putcontig8bitycbcr44tile","title":"libtiff signed integer overflow in putcontig8bitYCbCr44tile","severity":"high","exploited":false,"published_at":"2026-03-24T15:16:39.693+00:00","url":"https://junglewise.ai/threats/cve-2026-4775-libtiff-signed-integer-overflow-in-putcontig8bitycbcr44tile"},{"cve":"CVE-2016-9453","cvss":7.8,"slug":"cve-2016-9453-libtiff-out-of-bounds-write-in-tiff2pdf","title":"LibTIFF out-of-bounds write in tiff2pdf","severity":"high","exploited":false,"published_at":"2017-01-27T17:59:00.337+00:00","url":"https://junglewise.ai/threats/cve-2016-9453-libtiff-out-of-bounds-write-in-tiff2pdf"},{"cve":"CVE-2023-52356","cvss":7.5,"slug":"cve-2023-52356-libtiff-heap-buffer-overflow-in-tiffreadrgbatileext","title":"libtiff heap buffer overflow in TIFFReadRGBATileExt","severity":"high","exploited":false,"published_at":"2024-01-25T20:15:39.063+00:00","url":"https://junglewise.ai/threats/cve-2023-52356-libtiff-heap-buffer-overflow-in-tiffreadrgbatileext"},{"cve":"CVE-2016-9448","cvss":7.5,"slug":"cve-2016-9448-libtiff-null-pointer-dereference-in-tifffetchnormaltag","title":"LibTiff NULL pointer dereference in TIFFFetchNormalTag","severity":"high","exploited":false,"published_at":"2017-01-27T17:59:00.29+00:00","url":"https://junglewise.ai/threats/cve-2016-9448-libtiff-null-pointer-dereference-in-tifffetchnormaltag"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}