CVE-2014-8128: Libtiff
Medium severity, CVSS 6.5. EPSS: 3.9% chance of exploitation in the next 30 days.
LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.
Affected products
- Libtiff Libtiff: before 4.0.4 (fixed in 4.0.4)
Published 2020-02-12. Last modified 2026-06-17.