Skip to main content

Vendor archive

libpng CVEs

Beta · best-effort

59 CVEs tagged to vendor libpng2 Critical, 21 High, 35 Medium, 1 Low, 0 Unrated.

CVE-2026-34757

Published Apr 9, 2026

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a…

CVSS 5.1 · Medium
evidence mentions
7
Buzz score
40.3
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-33636

Published Mar 26, 2026

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an o…

CVSS 7.6 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-33416

Published Mar 26, 2026

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_…

CVSS 7.5 · High
evidence mentions
7
Buzz score
35.3
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-25646

Published Feb 10, 2026

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read…

CVSS 8.3 · High
evidence mentions
60
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2025-28164

Published Jan 27, 2026

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-28162

Published Jan 27, 2026

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-22801

Published Jan 12, 2026

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an inte…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22695

Published Jan 12, 2026

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.51 to 1.6.53, there is a heap…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-66293

Published Dec 3, 2025

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-65018

Published Nov 25, 2025

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, th…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64720

Published Nov 25, 2025

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64506

Published Nov 25, 2025

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64505

Published Nov 25, 2025

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6129

Published Jan 11, 2019

png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14048

Published Jul 13, 2018

An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10087

Published Jan 30, 2017

The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-3751

Published Jul 11, 2016

Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8540

Published Apr 14, 2016

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, a…

CVSS 8.8 · High
Showing 1-25 of 59 CVEsPage 1 of 3