cbcvebase.
CVE-2014-8128
published 2020-02-12

CVE-2014-8128: LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service…

PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.99%
77.3th percentile
LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.

Affected

5 ranges
VendorProductVersion rangeFixed in
appleios
appleos_x_yosemite_v10.10.4_and_security_update_2015-005
debiantiff< tiff 4.0.3-12.3 (bookworm)tiff 4.0.3-12.3 (bookworm)
libtifflibtiff< 4.0.44.0.4
libtifflibtiff

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM