CVE-2016-6223: Libtiff
Critical severity, CVSS 9.1. EPSS: 3.3% chance of exploitation in the next 30 days.
The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a negative index in a file-content buffer.
Affected products
- Libtiff Libtiff: up to and including 4.0.6
Published 2017-01-23. Last modified 2026-06-17.