← All CVEs

CVE-2013-1960

high · 9.3

Heap-based buffer overflow in the t2p_process_jpeg_strip function in tiff2pdf in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image file.

9.3
CVSS
11.8%
EPSS (exploit prob.)
96th
EPSS percentile
2013-07-03
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
remotesensinglibtiff<= 4.0.3
remotesensinglibtiff3.4
remotesensinglibtiff3.4
remotesensinglibtiff3.4
remotesensinglibtiff3.4
remotesensinglibtiff3.4
remotesensinglibtiff3.4
remotesensinglibtiff3.4
remotesensinglibtiff3.4
remotesensinglibtiff3.4
remotesensinglibtiff3.4
remotesensinglibtiff3.4
remotesensinglibtiff3.5.1
remotesensinglibtiff3.5.2
remotesensinglibtiff3.5.3
remotesensinglibtiff3.5.4
remotesensinglibtiff3.5.5
remotesensinglibtiff3.5.6
remotesensinglibtiff3.5.6
remotesensinglibtiff3.5.7
remotesensinglibtiff3.5.7
remotesensinglibtiff3.5.7
remotesensinglibtiff3.5.7
remotesensinglibtiff3.5.7
remotesensinglibtiff3.5.7
remotesensinglibtiff3.6.0
remotesensinglibtiff3.6.0
remotesensinglibtiff3.6.0
remotesensinglibtiff3.6.1
remotesensinglibtiff3.7.0
remotesensinglibtiff3.7.0
remotesensinglibtiff3.7.0
remotesensinglibtiff3.7.0
remotesensinglibtiff3.7.1
remotesensinglibtiff3.7.2
remotesensinglibtiff3.7.3
remotesensinglibtiff3.7.4
remotesensinglibtiff3.8.0
remotesensinglibtiff3.8.1
remotesensinglibtiff3.8.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-1960