The following table lists the changes that have been made to the
CVE-2025-9165 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Aug. 19, 2025
Action Type Old Value New Value Added Description A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. Added CVSS V4.0 AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Added CVSS V2 (AV:L/AC:L/Au:S/C:N/I:N/A:P) Added CWE CWE-404 Added CWE CWE-401 Added Reference http://www.libtiff.org/ Added Reference https://drive.google.com/file/d/1FWhmkzksH8-qU0ZM6seBzGNB3aPnX3G8/view?usp=sharing Added Reference https://gitlab.com/libtiff/libtiff/-/commit/ed141286a37f6e5ddafb5069347ff5d587e7a4e0 Added Reference https://gitlab.com/libtiff/libtiff/-/issues/728 Added Reference https://gitlab.com/libtiff/libtiff/-/merge_requests/747 Added Reference https://vuldb.com/?ctiid.320543 Added Reference https://vuldb.com/?id.320543 Added Reference https://vuldb.com/?submit.630506 Added Reference https://vuldb.com/?submit.630507