<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:39:28.178010+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-09847</id>
    <title>bdu:2025-09847</title>
    <updated>2026-10-02T13:39:28.196435+00:00</updated>
    <content>bdu:2025-09847</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-09847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</id>
    <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T13:39:28.196474+00:00</updated>
    <content>certfr-2025-avi-0969</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-249043</id>
    <title>EUVD-2026-249043</title>
    <updated>2026-10-02T13:39:28.196492+00:00</updated>
    <content>EUVD-2026-249043</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-249043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-8534</id>
    <title>fkie_cve-2025-8534</title>
    <updated>2026-10-02T13:39:28.196503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-8534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xgh3-993q-r2x8</id>
    <title>GHSA-xgh3-993q-r2x8</title>
    <updated>2026-10-02T13:39:28.196535+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xgh3-993q-r2x8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-8534</id>
    <title>msrc_CVE-2025-8534 — libtiff tiff2ps tiff2ps.c PS_Lvl2page null pointer dereference</title>
    <updated>2026-10-02T13:39:28.196555+00:00</updated>
    <content>msrc_CVE-2025-8534</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-8534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2048</id>
    <title>OESA-2025-2048 — libtiff security update</title>
    <updated>2026-10-02T13:39:28.196571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: libtiff</p>
<p>This  provides support for the Tag Image File Format (TIFF), a widely
used format for storing image data. The latest version of the TIFF specification
is available on-line in several different formats.And contains command-line programs
for manipulating TIFF format image files using the libtiff library.

Security Fix(es):</p>
<p>LibTIFF is a library for reading and writing TIFF (label image file format) files that are open source. This library contains some command-line tools for handling TIFF files.
 There is a security vulnerability in the 4.6.0 version of LibTIFF, which originates from the dereference of the null pointer of the function PS_Lvl2page in the file tools/tiff2ps.c.(CVE-2025-8534)</p>
<p>A vulnerability was found in LibTIFF up to 4.5.1 (Image Processing Software). It has been rated as critical.Using CWE to declare the problem leads to CWE-121. A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).Impacted is confidentiality, integrity, and availability.Applying the patch 8a7a48d7a645992ca83062b3a1873c951661e2b3 is able to eliminate this problem. The bugfix is ready for download at gitlab.com.(CVE-2025-8851)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15486-1</id>
    <title>openSUSE-SU-2025:15486-1 — libtiff-devel-32bit-4.7.0-8.1 on GA media</title>
    <updated>2026-10-02T13:39:28.196600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libtiff-devel-32bit-4.7.0-8.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15486-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03346-1</id>
    <title>SUSE-SU-2025:03346-1 — Security update for tiff</title>
    <updated>2026-10-02T13:39:28.196618+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tiff</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03346-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8534</id>
    <title>UBUNTU-CVE-2025-8534</title>
    <updated>2026-10-02T13:39:28.196632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: gdal, Ubuntu:Pro:14.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: gdal, Ubuntu:16.04:LTS: texmaker, Ubuntu:Pro:18.04:LTS: tiff, Ubuntu:18.04:LTS: neuron, Ubuntu:Pro:18.04:LTS: qtwebengine-opensource-src, Ubuntu:Pro:18.04:LTS: texmaker, Ubuntu:Pro:20.04:LTS: tiff and 15 more</p>
<p>A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1717</id>
    <title>WID-SEC-W-2025-1717 — libTIFF (tiff2ps): Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T13:39:28.196679+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in libTIFF ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1717"/>
  </entry>
</feed>
