Multiple stack-based buffer overflows exist in the TIFF library (libtiff) before version 3.8.2, as used in Adobe Reader 9.3.0 and other products. One of the vulnerable functions is TIFFFetchShortPair in tif_dirread.c, which can be exploited by providing a large tdir_count value. This allows context-dependent attackers to execute arbitrary code or cause a denial of service via crafted TIFF files.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (modules/exploits/apple_ios/browser/safari_libtiff.rb) that exploits a buffer overflow vulnerability in the libtiff library used by MobileSafari on early Apple iPhone firmware (1.00, 1.01, 1.02, 1.1.1). The module acts as an HTTP server, delivering a specially crafted TIFF image to the target device. When a vulnerable iPhone user visits the attacker's server with MobileSafari, the malicious TIFF triggers a buffer overflow, allowing the attacker to execute arbitrary ARM shellcode on the device. The exploit is operational, with a hardcoded payload and specific targeting of early iOS versions. The main attack vector is browser-based (drive-by download via HTTP), and the only fingerprintable endpoint is the attacker's HTTP server. The code is structured as a typical Metasploit exploit module, with methods for handling HTTP requests, generating the malicious TIFF, and managing payload delivery.
This repository contains a single Metasploit module (modules/exploits/apple_ios/email/mobilemail_libtiff.rb) that exploits a buffer overflow vulnerability in the libtiff library used by Apple's iPhone MobileMail application (CVE-2006-3459). The exploit targets iPhones running firmware versions 1.00, 1.01, 1.02, and 1.1.1. The module works by generating a malicious TIFF file containing custom shellcode, which is then attached to an email and sent to the target via SMTP. When the target device processes the email and opens the attachment, the buffer overflow is triggered, allowing arbitrary code execution. The exploit is highly weaponized, leveraging Metasploit's payload system for customizable post-exploitation actions. The code is written in Ruby and is structured as a standard Metasploit exploit module, making it easy to use within the framework. No hardcoded IPs, domains, or URLs are present; the main fingerprintable endpoint is the malicious TIFF file delivered via email.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.