CVE-2025-9900High· 8.8▾ TwilightA flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
0.7% → 0.8%
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file.
By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-25262Medium· 6.9Memory corruption while processing a crafted ELF file in the Primary Bootloader.
CVE-2026-94146High· 8.8A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3
CVE-2026-94142High· 8.8A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200
CVE-2026-94129High· 8.8A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800
CVE-2026-94128High· 8.8A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500
CVE-2026-48977High· 7.7OpenSlide is a C library for reading whole slide image files