Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 29 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-190 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 26 Aug 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-122 CWE-680 |
Wed, 26 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Buffer Overflow in libtiff YCbCr Conversion | libtiff: libtiff: Arbitrary code execution via crafted TIFF image |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 24 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Buffer Overflow in libtiff YCbCr Conversion | |
| First Time appeared |
Libtiff
Libtiff libtiff |
|
| Weaknesses | CWE-122 CWE-680 |
|
| Vendors & Products |
Libtiff
Libtiff libtiff |
Mon, 24 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-27T19:05:00.091Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-52492
Updated: 2026-08-27T19:04:39.807Z
Status : Received
Published: 2026-08-24T21:17:19.927
Modified: 2026-08-27T20:17:48.473
Link: CVE-2026-52492
OpenCVE Enrichment
Updated: 2026-08-28T19:15:05Z