CVE-2014-8128: Libtiff

Medium severity, CVSS 6.5. EPSS: 3.9% chance of exploitation in the next 30 days.

LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.

Affected products

  • Libtiff Libtiff: before 4.0.4 (fixed in 4.0.4)

Published 2020-02-12. Last modified 2026-06-17.