<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:48:30.601414+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:0095</id>
    <title>ALSA-2023:0095 — Moderate: libtiff security update</title>
    <updated>2026-10-02T23:48:30.615470+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: libtiff, AlmaLinux:8: libtiff-devel, AlmaLinux:8: libtiff-tools</p>
<p>The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.</p>
<p>Security Fix(es):</p>
<p>* LibTiff: DoS from Divide By Zero Error (CVE-2022-2056, CVE-2022-2057, CVE-2022-2058)
* libtiff: Double free or corruption in rotateImage() function at tiffcrop.c (CVE-2022-2519)
* libtiff: uint32_t underflow leads to out of bounds read and write in tiffcrop.c (CVE-2022-2867)
* libtiff: tiffcrop.c has uint32_t underflow which leads to out of bounds read and write in extractContigSamples8bits() (CVE-2022-2869)
* libtiff: tiffcrop: heap-buffer-overflow in extractImageSection in tiffcrop.c (CVE-2022-2953)
* libtiff: Assertion fail in rotateImage() function at tiffcrop.c (CVE-2022-2520)
* libtiff: Invalid pointer free operation in TIFFClose() at tif_close.c (CVE-2022-2521)
* libtiff: Invalid crop_width and/or crop_length could cause an out-of-bounds read in reverseSamples16bits() (CVE-2022-2868)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:0095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05416</id>
    <title>bdu:2023-05416</title>
    <updated>2026-10-02T23:48:30.615537+00:00</updated>
    <content>bdu:2023-05416</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05416"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-2869</id>
    <title>Withdrawn: BELL-CVE-2022-2869 — CVE-2022-2869 does not affect BellSoft software</title>
    <updated>2026-10-02T23:48:30.615554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-2869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1103</id>
    <title>certfr-2024-avi-1103 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T23:48:30.615569+00:00</updated>
    <content>certfr-2024-avi-1103</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-1103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-12514</id>
    <title>EUVD-2026-12514</title>
    <updated>2026-10-02T23:48:30.615582+00:00</updated>
    <content>EUVD-2026-12514</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-12514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2869</id>
    <title>fkie_cve-2022-2869</title>
    <updated>2026-10-02T23:48:30.615593+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-2869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m98c-rvx4-4xmr</id>
    <title>GHSA-m98c-rvx4-4xmr</title>
    <updated>2026-10-02T23:48:30.615615+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m98c-rvx4-4xmr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-2869</id>
    <title>gsd-2022-2869</title>
    <updated>2026-10-02T23:48:30.615630+00:00</updated>
    <content>gsd-2022-2869</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-2869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-2869</id>
    <title>msrc_CVE-2022-2869 — libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSample…</title>
    <updated>2026-10-02T23:48:30.615639+00:00</updated>
    <content>msrc_CVE-2022-2869</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-2869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1869</id>
    <title>OESA-2022-1869 — libtiff security update</title>
    <updated>2026-10-02T23:48:30.615654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: libtiff, openEuler:20.03-LTS-SP3: libtiff, openEuler:22.03-LTS: libtiff</p>
<p>Security Fix(es):

libtiff&amp;apos;s tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation.(CVE-2022-2867)

libtiff&amp;apos;s tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.(CVE-2022-2868)

libtiff&amp;apos;s tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation.(CVE-2022-2869)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13381-1</id>
    <title>openSUSE-SU-2024:13381-1 — libtiff-devel-32bit-4.6.0-2.1 on GA media</title>
    <updated>2026-10-02T23:48:30.615682+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libtiff-devel-32bit-4.6.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13381-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3679-1</id>
    <title>SUSE-SU-2022:3679-1 — Security update for tiff</title>
    <updated>2026-10-02T23:48:30.615702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tiff</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3679-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2869</id>
    <title>UBUNTU-CVE-2022-2869</title>
    <updated>2026-10-02T23:48:30.615719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: tiff, Ubuntu:18.04:LTS: tiff, Ubuntu:20.04:LTS: tiff, Ubuntu:22.04:LTS: tiff</p>
<p>libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1061</id>
    <title>WID-SEC-W-2022-1061 — libTIFF: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-02T23:48:30.615743+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in libTIFF ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1061"/>
  </entry>
</feed>
