Libpng

Libpng

48 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.79%
  • Veröffentlicht 15.01.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creation of crafted PNG files with k...

Exploit
  • EPSS 1.71%
  • Veröffentlicht 11.09.2008 01:13:47
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the...

  • EPSS 6.33%
  • Veröffentlicht 14.04.2008 16:05:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG file with zero length "unknown" chunks, which...

  • EPSS 10.46%
  • Veröffentlicht 08.10.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Certain chunk handlers in libpng before 1.0.29 and 1.2.x before 1.2.21 allow remote attackers to cause a denial of service (crash) via crafted (1) pCAL (png_handle_pCAL), (2) sCAL (png_handle_sCAL), (3) tEXt (png_push_read_tEXt), (4) iTXt (png_handle...

  • EPSS 15.26%
  • Veröffentlicht 08.10.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.

  • EPSS 3.12%
  • Veröffentlicht 08.10.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.2.22 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image, due to an incorrect fix for CVE-2007-5266.

  • EPSS 13.05%
  • Veröffentlicht 08.10.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.0.29 beta1 and 1.2.x before 1.2.21 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image that prevents a n...

  • EPSS 1.83%
  • Veröffentlicht 18.08.2004 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.