<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:39:10 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-09847</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09847</link>
      <description>bdu:2025-09847</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09847</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</link>
      <description>certfr-2025-avi-0969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</guid>
    </item>
    <item>
      <title>EUVD-2026-249043</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-249043</link>
      <description>EUVD-2026-249043</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-249043</guid>
    </item>
    <item>
      <title>fkie_cve-2025-8534</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-8534</link>
      <description>&lt;p&gt;A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that &amp;#34;[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. &amp;#34;rD&amp;#34;) option is used.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that &amp;#34;[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. &amp;#34;rD&amp;#34;) option is used.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-8534</guid>
    </item>
    <item>
      <title>GHSA-xgh3-993q-r2x8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xgh3-993q-r2x8</link>
      <description>&lt;p&gt;A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that &amp;#34;[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. &amp;#34;rD&amp;#34;) option is used.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that &amp;#34;[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. &amp;#34;rD&amp;#34;) option is used.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xgh3-993q-r2x8</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-8534 — libtiff tiff2ps tiff2ps.c PS_Lvl2page null pointer dereference</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-8534</link>
      <description>msrc_CVE-2025-8534</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-8534</guid>
    </item>
    <item>
      <title>OESA-2025-2048 — libtiff security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2048</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: libtiff&lt;/p&gt;
&lt;p&gt;This  provides support for the Tag Image File Format (TIFF), a widely
used format for storing image data. The latest version of the TIFF specification
is available on-line in several different formats.And contains command-line programs
for manipulating TIFF format image files using the libtiff library.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;LibTIFF is a library for reading and writing TIFF (label image file format) files that are open source. This library contains some command-line tools for handling TIFF files.
 There is a security vulnerability in the 4.6.0 version of LibTIFF, which originates from the dereference of the null pointer of the function PS_Lvl2page in the file tools/tiff2ps.c.(CVE-2025-8534)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in LibTIFF up to 4.5.1 (Image Processing Software). It has been rated as critical.Using CWE to declare the problem leads to CWE-121. A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).Impacted is confidentiality, integrity, and availability.Applying the patch 8a7a48d7a645992ca83062b3a1873c951661e2b3 is able to eliminate this problem. The bugfix is ready for download at gitlab.com.(CVE-2025-8851)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: libtiff&lt;/p&gt;
&lt;p&gt;This  provides support for the Tag Image File Format (TIFF), a widely
used format for storing image data. The latest version of the TIFF specification
is available on-line in several different formats.And contains command-line programs
for manipulating TIFF format image files using the libtiff library.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;LibTIFF is a library for reading and writing TIFF (label image file format) files that are open source. This library contains some command-line tools for handling TIFF files.
 There is a security vulnerability in the 4.6.0 version of LibTIFF, which originates from the dereference of the null pointer of the function PS_Lvl2page in the file tools/tiff2ps.c.(CVE-2025-8534)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in LibTIFF up to 4.5.1 (Image Processing Software). It has been rated as critical.Using CWE to declare the problem leads to CWE-121. A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).Impacted is confidentiality, integrity, and availability.Applying the patch 8a7a48d7a645992ca83062b3a1873c951661e2b3 is able to eliminate this problem. The bugfix is ready for download at gitlab.com.(CVE-2025-8851)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2048</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15486-1 — libtiff-devel-32bit-4.7.0-8.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15486-1</link>
      <description>&lt;p&gt;libtiff-devel-32bit-4.7.0-8.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libtiff-devel-32bit-4.7.0-8.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15486-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03346-1 — Security update for tiff</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03346-1</link>
      <description>&lt;p&gt;Security update for tiff&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tiff&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03346-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-8534</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8534</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gdal, Ubuntu:Pro:14.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: gdal, Ubuntu:16.04:LTS: texmaker, Ubuntu:Pro:18.04:LTS: tiff, Ubuntu:18.04:LTS: neuron, Ubuntu:Pro:18.04:LTS: qtwebengine-opensource-src, Ubuntu:Pro:18.04:LTS: texmaker, Ubuntu:Pro:20.04:LTS: tiff and 15 more&lt;/p&gt;
&lt;p&gt;A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that &amp;#34;[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. &amp;#34;rD&amp;#34;) option is used.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gdal, Ubuntu:Pro:14.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: gdal, Ubuntu:16.04:LTS: texmaker, Ubuntu:Pro:18.04:LTS: tiff, Ubuntu:18.04:LTS: neuron, Ubuntu:Pro:18.04:LTS: qtwebengine-opensource-src, Ubuntu:Pro:18.04:LTS: texmaker, Ubuntu:Pro:20.04:LTS: tiff and 15 more&lt;/p&gt;
&lt;p&gt;A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that &amp;#34;[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. &amp;#34;rD&amp;#34;) option is used.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8534</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1717 — libTIFF (tiff2ps): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1717</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in libTIFF ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in libTIFF ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1717</guid>
    </item>
  </channel>
</rss>
