CVE-2016-9535General(libtiff / libtiff)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libtiff

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
libtiff

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-11: 1Technical Details · 2026-02-11: 102-11
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • kawn@kawn2020
    General

    #windowsupdate #microsoft ■既存の脆弱性情報の更新 ・CVE-2016-9535 MITRE CVE-2016-9535: LibTIFF ヒープ バッファ オーバーフローの脆弱性 ・CVE-2025-2884 Cert CC: CVE-2025-2884 TPM2.0 リファレンス実装における境界外読み取りの脆弱性 ■新規セキュリティアドバイザリの公開 なし

    Post summary

    The post lists two known CVEs—CVE‑2016‑9535 (LibTIFF heap overflow) and CVE‑2025‑2884 (TPM2.0 out‑of‑bounds read)—without providing details on patches, exploits, or PoCs.

    1000070
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibtifflibtiff4.0.6--

Explore more