CVE-2018-13785
- EPSS 2.92%
- Veröffentlicht 09.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:47:58
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
CVE-2016-10087
- EPSS 0.95%
- Veröffentlicht 30.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text c...
CVE-2016-3751
- EPSS 0.14%
- Veröffentlicht 11.07.2016 01:59:51
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Sig...
CVE-2015-8540
- EPSS 13.55%
- Veröffentlicht 14.04.2016 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impa...
CVE-2015-8472
- EPSS 4.8%
- Veröffentlicht 21.01.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or ...
- EPSS 0.93%
- Veröffentlicht 24.11.2015 20:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which trigge...
CVE-2015-8126
- EPSS 4.95%
- Veröffentlicht 13.11.2015 03:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a den...
CVE-2015-0973
- EPSS 2.01%
- Veröffentlicht 18.01.2015 18:59:03
- Zuletzt bearbeitet 09.06.2025 16:15:24
Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-94...
- EPSS 3.3%
- Veröffentlicht 10.01.2015 19:59:00
- Zuletzt bearbeitet 09.06.2025 16:15:24
Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers to execute arbitrary code via a "very wide interlaced" PNG image.
- EPSS 0.57%
- Veröffentlicht 06.05.2014 14:55:05
- Zuletzt bearbeitet 09.06.2025 16:15:24
Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png_set_sPLT or (2) png_set_text_2 function, which triggers a heap-based buffer overflow.