<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:39:24 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:17675 — Important: compat-libtiff3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:17675</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: compat-libtiff3&lt;/p&gt;
&lt;p&gt;The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libtiff: Libtiff Write-What-Where (CVE-2025-9900)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: compat-libtiff3&lt;/p&gt;
&lt;p&gt;The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libtiff: Libtiff Write-What-Where (CVE-2025-9900)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:17675</guid>
    </item>
    <item>
      <title>bdu:2025-13921</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13921</link>
      <description>bdu:2025-13921</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13921</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-9900</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-9900</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: tiff, Alpaquita:stream: tiff, BellSoft Hardened Containers:25: tiff, BellSoft Hardened Containers:stream: tiff&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: tiff, Alpaquita:stream: tiff, BellSoft Hardened Containers:25: tiff, BellSoft Hardened Containers:stream: tiff&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-9900</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0938 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0938</link>
      <description>certfr-2025-avi-0938</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0938</guid>
    </item>
    <item>
      <title>EUVD-2026-331199</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331199</link>
      <description>EUVD-2026-331199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331199</guid>
    </item>
    <item>
      <title>fkie_cve-2025-9900</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9900</link>
      <description>&lt;p&gt;A flaw was found in Libtiff. This vulnerability is a &amp;#34;write-what-where&amp;#34; condition, triggered when the library processes a specially crafted TIFF image file.&lt;/p&gt;
&lt;p&gt;By providing an abnormally large image height value in the file&amp;#39;s metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Libtiff. This vulnerability is a &amp;#34;write-what-where&amp;#34; condition, triggered when the library processes a specially crafted TIFF image file.&lt;/p&gt;
&lt;p&gt;By providing an abnormally large image height value in the file&amp;#39;s metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-9900</guid>
    </item>
    <item>
      <title>GHSA-qc8j-wvjf-7jfj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qc8j-wvjf-7jfj</link>
      <description>&lt;p&gt;A flaw was found in Libtiff. This vulnerability is a &amp;#34;write-what-where&amp;#34; condition, triggered when the library processes a specially crafted TIFF image file.&lt;/p&gt;
&lt;p&gt;By providing an abnormally large image height value in the file&amp;#39;s metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Libtiff. This vulnerability is a &amp;#34;write-what-where&amp;#34; condition, triggered when the library processes a specially crafted TIFF image file.&lt;/p&gt;
&lt;p&gt;By providing an abnormally large image height value in the file&amp;#39;s metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qc8j-wvjf-7jfj</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-9900 — Libtiff: libtiff write-what-where</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-9900</link>
      <description>msrc_CVE-2025-9900</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-9900</guid>
    </item>
    <item>
      <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</link>
      <description>NCSC-2026-0022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0022</guid>
    </item>
    <item>
      <title>OESA-2025-2400 — libtiff security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2400</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libtiff&lt;/p&gt;
&lt;p&gt;This  provides support for the Tag Image File Format (TIFF), a widely used format for storing image data. The latest version of the TIFF specification is available on-line in several different formats.And contains command-line programs for manipulating TIFF format image files using the libtiff library.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability classified as critical has been found in LibTIFF (Image Processing Software) (unknown version).CWE is classifying the issue as CWE-123. Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.This is going to have an impact on confidentiality, integrity, and availability.There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2025-9900)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libtiff&lt;/p&gt;
&lt;p&gt;This  provides support for the Tag Image File Format (TIFF), a widely used format for storing image data. The latest version of the TIFF specification is available on-line in several different formats.And contains command-line programs for manipulating TIFF format image files using the libtiff library.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability classified as critical has been found in LibTIFF (Image Processing Software) (unknown version).CWE is classifying the issue as CWE-123. Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.This is going to have an impact on confidentiality, integrity, and availability.There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2025-9900)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2400</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15635-1 — libtiff-devel-32bit-4.7.1-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15635-1</link>
      <description>&lt;p&gt;libtiff-devel-32bit-4.7.1-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libtiff-devel-32bit-4.7.1-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15635-1</guid>
    </item>
    <item>
      <title>RHSA-2025:17651 — Red Hat Security Advisory: compat-libtiff3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:17651</link>
      <description>&lt;p&gt;libtiff: Libtiff Write-What-Where&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libtiff: Libtiff Write-What-Where&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:17651</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:20971-1 — Security update for tiff</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:20971-1</link>
      <description>&lt;p&gt;Security update for tiff&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tiff&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:20971-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-9900</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9900</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gdal, Ubuntu:Pro:14.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: gdal, Ubuntu:Pro:18.04:LTS: tiff, Ubuntu:Pro:18.04:LTS: qtwebengine-opensource-src, Ubuntu:Pro:18.04:LTS: texmaker, Ubuntu:Pro:20.04:LTS: tiff, Ubuntu:Pro:20.04:LTS: qtwebengine-opensource-src, Ubuntu:Pro:20.04:LTS: texmaker and 11 more&lt;/p&gt;
&lt;p&gt;A flaw was found in Libtiff. This vulnerability is a &amp;#34;write-what-where&amp;#34; condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file&amp;#39;s metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gdal, Ubuntu:Pro:14.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: gdal, Ubuntu:Pro:18.04:LTS: tiff, Ubuntu:Pro:18.04:LTS: qtwebengine-opensource-src, Ubuntu:Pro:18.04:LTS: texmaker, Ubuntu:Pro:20.04:LTS: tiff, Ubuntu:Pro:20.04:LTS: qtwebengine-opensource-src, Ubuntu:Pro:20.04:LTS: texmaker and 11 more&lt;/p&gt;
&lt;p&gt;A flaw was found in Libtiff. This vulnerability is a &amp;#34;write-what-where&amp;#34; condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file&amp;#39;s metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9900</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2110 — LibTiff: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2110</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in LibTiff ausnutzen, um einen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in LibTiff ausnutzen, um einen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2110</guid>
    </item>
  </channel>
</rss>
