Skip to main content

Vendor archive

libpng CVEs

Beta · best-effort

59 CVEs tagged to vendor libpng2 Critical, 21 High, 35 Medium, 1 Low, 0 Unrated.

CVE-2015-8472

Published Jan 21, 2016

Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allow…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7981

Published Nov 24, 2015

The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2014-9495

Published Jan 10, 2015

Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7354

Published May 6, 2014

Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png_set_sPLT or (2) png_set_text_…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7353

Published May 6, 2014

Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause a denial of service (segmentat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0333

Published Feb 27, 2014

The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service (infinite loop and CPU…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6954

Published Jan 12, 2014

The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chun…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3464

Published Jul 22, 2012

Off-by-one error in the png_formatted_warning function in pngerror.c in libpng 1.5.4 through 1.5.7 might allow remote attackers to cause a denial of service (application crash) an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3048

Published May 29, 2012

The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remote attackers to cause a denial…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3045

Published Mar 22, 2012

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote att…

CVSS 8.8 · High

CVE-2009-5063

Published Aug 31, 2011

Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segment…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7244

Published Aug 31, 2011

Memory leak in pngwutil.c in libpng 1.2.13beta1, and other versions before 1.2.15beta3, allows context-dependent attackers to cause a denial of service (memory leak or segmentatio…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0408

Published Jan 18, 2011

pngrtran.c in libpng 1.5.x before 1.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted palette-based PNG…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2249

Published Jun 30, 2010

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PN…

CVSS 6.5 · Medium

CVE-2010-1205

Published Jun 30, 2010

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG…

CVSS 9.8 · Critical

CVE-2009-2042

Published Jun 12, 2009

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain ro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0040

Published Feb 22, 2009

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Showing 26-50 of 59 CVEsPage 2 of 3