CVE-2021-4214
- EPSS 0.08%
- Veröffentlicht 24.08.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:37:10
A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.
CVE-2017-12652
- EPSS 0.62%
- Veröffentlicht 10.07.2019 15:15:10
- Zuletzt bearbeitet 09.06.2025 16:15:26
libpng before 1.6.32 does not properly check the length of chunks against the user limit.
CVE-2018-14550
- EPSS 1.78%
- Veröffentlicht 10.07.2019 12:15:10
- Zuletzt bearbeitet 21.11.2024 03:49:17
An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.
CVE-2019-7317
- EPSS 0.99%
- Veröffentlicht 04.02.2019 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:00
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
CVE-2019-6129
- EPSS 0.43%
- Veröffentlicht 11.01.2019 05:29:01
- Zuletzt bearbeitet 21.11.2024 04:45:59
png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.
CVE-2018-14048
- EPSS 0.9%
- Veröffentlicht 13.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:30
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
CVE-2018-13785
- EPSS 2.92%
- Veröffentlicht 09.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:47:58
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
CVE-2016-10087
- EPSS 1.85%
- Veröffentlicht 30.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text c...
CVE-2016-3751
- EPSS 0.14%
- Veröffentlicht 11.07.2016 01:59:51
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Sig...
CVE-2015-8540
- EPSS 13.3%
- Veröffentlicht 14.04.2016 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impa...