İçeriğe atla
Noroxi

libpng kayıtları

libpng üreticisine ait 59 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
9
Düzeltme kaydı olan
%84,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

59 kayıt
  • CVE-2010-1205
    52Planlayın

    Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attack

    KritikCVSS 9,8Kavram kanıtıEPSS %43

    libpng · libpng30 Haz 2010

  • CVE-2017-12652
    40Planlayın

    libpng before 1.6.32 does not properly check the length of chunks against the user limit.

    KritikCVSS 9,8İstismar yokEPSS %4

    libpng · libpng10 Tem 2019

  • CVE-2015-8540
    37İzleyin

    Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1

    YüksekCVSS 8,8İstismar yokEPSS %6

    libpng · libpng14 Nis 2016

  • CVE-2011-2692
    36İzleyin

    The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 do

    YüksekCVSS 8,8İstismar yokEPSS %4

    libpng · libpng17 Tem 2011

  • CVE-2015-0973
    36İzleyin

    Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent at

    YüksekCVSS 8,8İstismar yokEPSS %4

    libpng · libpng18 Oca 2015

  • CVE-2014-9495
    36İzleyin

    Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems,

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    libpng · libpng10 Oca 2015

  • CVE-2011-3045
    36İzleyin

    Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.8

    YüksekCVSS 8,8İstismar yokEPSS %4

    google · chrome22 Mar 2012

  • CVE-2018-14550
    36İzleyin

    An issue has been found in third-party PNM decoding associated with libpng 1.6.35.

    YüksekCVSS 8,8İstismar yokEPSS %4

    libpng · libpng10 Tem 2019

  • CVE-2011-2690
    36İzleyin

    Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application

    YüksekCVSS 8,8İstismar yokEPSS %3

    libpng · libpng17 Tem 2011

  • CVE-2015-8126
    33İzleyin

    Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3

    YüksekCVSS 7,5İstismar yokEPSS %10

    libpng · libpng12 Kas 2015

  • CVE-2026-25646
    33İzleyin

    LIBPNG has a heap buffer overflow in png_set_quantize

    YüksekCVSS 8,3İstismar yokEPSS %1

    libpng · libpng10 Şub 2026

  • CVE-2008-1382
    32İzleyin

    libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial

    YüksekCVSS 7,5İstismar yokEPSS %6

    libpng · libpng14 Nis 2008

  • CVE-2016-10087
    32İzleyin

    The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.

    YüksekCVSS 7,5İstismar yokEPSS %5

    libpng · libpng30 Oca 2017

  • CVE-2015-8472
    31İzleyin

    Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x befor

    YüksekCVSS 7,3İstismar yokEPSS %6

    libpng · libpng21 Oca 2016

  • CVE-2011-3464
    31İzleyin

    Off-by-one error in the png_formatted_warning function in pngerror.c in libpng 1.5.4 through 1.5.7 might allow remote attackers to cause a d

    YüksekCVSS 7,5İstismar yokEPSS %3

    libpng · libpng22 Tem 2012

  • CVE-2016-3751
    31İzleyin

    Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befo

    YüksekCVSS 7,8İstismar yokEPSS %0

    libpng · libpng10 Tem 2016

  • CVE-2020-35511
    31İzleyin

    A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.

    YüksekCVSS 7,8İstismar yokEPSS %0

    libpng · pngcheck23 Ağu 2022

  • CVE-2026-22801
    31İzleyin

    LIBPNG has an integer truncation causing heap buffer over-read in png_image_write_*

    YüksekCVSS 7,8İstismar yokEPSS %0

    libpng · libpng12 Oca 2026

  • CVE-2026-33416
    30İzleyin

    LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`

    YüksekCVSS 7,5İstismar yokEPSS %1

    libpng · libpng26 Mar 2026

  • CVE-2026-33636
    30İzleyin

    LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64

    YüksekCVSS 7,6İstismar yokEPSS %0

    libpng · libpng26 Mar 2026

  • CVE-2011-3048
    29İzleyin

    The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 all

    OrtaCVSS 6,8İstismar yokEPSS %7

    libpng · libpng29 May 2012

  • CVE-2011-0408
    29İzleyin

    pngrtran.c in libpng 1.5.x before 1.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitra

    OrtaCVSS 6,8İstismar yokEPSS %6

    libpng · libpng18 Oca 2011

  • CVE-2008-6218
    29İzleyin

    Memory leak in the png_handle_tEXt function in pngrutil.c in libpng before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers t

    YüksekCVSS 7,1İstismar yokEPSS %2

    libpng · libpng20 Şub 2009

  • CVE-2009-0040
    28İzleyin

    The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-de

    OrtaCVSS 6,8İstismar yokEPSS %5

    libpng · libpng22 Şub 2009

  • CVE-2025-64720
    28İzleyin

    LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication

    YüksekCVSS 7,1Kavram kanıtıEPSS %0

    libpng · libpng24 Kas 2025