Vulnerability · NVD
CVE-2016-9535
CRITICAL 9.8
tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."
Attack vector : Network
No privileges required
No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
4.77%
above median
percentile 91.1%
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Server 2025 Fixed in 10.0.26100.6899
- Windows Server 2022 (Server Core installation) Fixed in 10.0.20348.4294
- Windows Server 2022 Fixed in 10.0.25398.1913
- Windows Server 2019 Fixed in 10.0.17763.7919
- Windows Server 2016 Fixed in 10.0.14393.8519
- Windows 11 25H2 · 2025-H2 Fixed in 10.0.26200.6899
- Windows 11 24H2 · 2024-H2 Fixed in 10.0.26100.6899
- Windows 11 23H2 · 2023-H2 Fixed in 10.0.22631.6060
- Windows 11 22H2 · 2022-H2 Fixed in 10.0.22621.6060
- Windows 10 22H2 · 2022-H2 Fixed in 10.0.19045.6456
- Windows 10 21H2 · 2021-H2 Fixed in 10.0.19044.6456
- Windows 10 1809 · 2018-09 Fixed in 10.0.17763.7919
- Windows 10 1607 · 2016-07 Fixed in 10.0.14393.8519