CVE-2025-9900
Libtiff Crafted Image Write-What-Where Vulnerability
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
A flaw in Libtiff allows attackers to write data to arbitrary memory locations by providing a specially crafted TIFF image, potentially leading to code execution or denial of service. This vulnerability is reachable through user interaction with a malicious image file.