libpng kayıtları
libpng üreticisine ait 59 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %84,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read9
- CWE-189 Numeric Errors8
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')6
- CWE-401 Missing Release of Memory after Effective Lifetime4
- CWE-476 NULL Pointer Dereference3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
59 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2010-1205Kavram kanıtı | Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attacklibpng · libpng · CWE-120 | Kritik9,8 | — | %43,4 | 30 Haz 2010 |
40Planlayın | CVE-2017-12652İstismar yok | libpng before 1.6.32 does not properly check the length of chunks against the user limit.libpng · libpng · CWE-20 | Kritik9,8 | — | %4,1 | 10 Tem 2019 |
37İzleyin | CVE-2015-8540İstismar yok | Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1libpng · libpng · CWE-189 | Yüksek8,8 | — | %6,5 | 14 Nis 2016 |
36İzleyin | CVE-2011-2692İstismar yok | The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 dolibpng · libpng · CWE-119 | Yüksek8,8 | — | %4,2 | 17 Tem 2011 |
36İzleyin | CVE-2015-0973İstismar yok | Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent atlibpng · libpng · CWE-119 | Yüksek8,8 | — | %4,1 | 18 Oca 2015 |
36İzleyin | CVE-2014-9495Kavram kanıtı | Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, libpng · libpng · CWE-119 | Yüksek8,8 | — | %4,1 | 10 Oca 2015 |
36İzleyin | CVE-2011-3045İstismar yok | Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.8google · chrome · CWE-190 | Yüksek8,8 | — | %3,6 | 22 Mar 2012 |
36İzleyin | CVE-2018-14550İstismar yok | An issue has been found in third-party PNM decoding associated with libpng 1.6.35.libpng · libpng · CWE-787 | Yüksek8,8 | — | %3,5 | 10 Tem 2019 |
36İzleyin | CVE-2011-2690İstismar yok | Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application libpng · libpng · CWE-120 | Yüksek8,8 | — | %3,3 | 17 Tem 2011 |
33İzleyin | CVE-2015-8126İstismar yok | Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3libpng · libpng · CWE-120 | Yüksek7,5 | — | %10,3 | 12 Kas 2015 |
33İzleyin | CVE-2026-25646İstismar yok | LIBPNG has a heap buffer overflow in png_set_quantizelibpng · libpng · CWE-122 | Yüksek8,3 | — | %0,7 | 10 Şub 2026 |
32İzleyin | CVE-2008-1382İstismar yok | libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial libpng · libpng · CWE-189 | Yüksek7,5 | — | %5,5 | 14 Nis 2008 |
32İzleyin | CVE-2016-10087İstismar yok | The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.libpng · libpng · CWE-476 | Yüksek7,5 | — | %5,1 | 30 Oca 2017 |
31İzleyin | CVE-2015-8472İstismar yok | Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x beforlibpng · libpng · CWE-119 | Yüksek7,3 | — | %6,1 | 21 Oca 2016 |
31İzleyin | CVE-2011-3464İstismar yok | Off-by-one error in the png_formatted_warning function in pngerror.c in libpng 1.5.4 through 1.5.7 might allow remote attackers to cause a dlibpng · libpng · CWE-189 | Yüksek7,5 | — | %3,1 | 22 Tem 2012 |
31İzleyin | CVE-2016-3751İstismar yok | Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befolibpng · libpng | Yüksek7,8 | — | %0,5 | 10 Tem 2016 |
31İzleyin | CVE-2020-35511İstismar yok | A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.libpng · pngcheck · CWE-126 | Yüksek7,8 | — | %0,4 | 23 Ağu 2022 |
31İzleyin | CVE-2026-22801İstismar yok | LIBPNG has an integer truncation causing heap buffer over-read in png_image_write_*libpng · libpng · CWE-125 | Yüksek7,8 | — | %0,1 | 12 Oca 2026 |
30İzleyin | CVE-2026-33416İstismar yok | LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`libpng · libpng · CWE-416 | Yüksek7,5 | — | %0,5 | 26 Mar 2026 |
30İzleyin | CVE-2026-33636İstismar yok | LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64libpng · libpng · CWE-125 | Yüksek7,6 | — | %0,4 | 26 Mar 2026 |
29İzleyin | CVE-2011-3048İstismar yok | The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 alllibpng · libpng · CWE-119 | Orta6,8 | — | %6,6 | 29 May 2012 |
29İzleyin | CVE-2011-0408İstismar yok | pngrtran.c in libpng 1.5.x before 1.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitralibpng · libpng · CWE-119 | Orta6,8 | — | %5,6 | 18 Oca 2011 |
29İzleyin | CVE-2008-6218İstismar yok | Memory leak in the png_handle_tEXt function in pngrutil.c in libpng before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers tlibpng · libpng · CWE-399 | Yüksek7,1 | — | %2,3 | 20 Şub 2009 |
28İzleyin | CVE-2009-0040İstismar yok | The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-delibpng · libpng · CWE-824 | Orta6,8 | — | %4,8 | 22 Şub 2009 |
28İzleyin | CVE-2025-64720Kavram kanıtı | LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplicationlibpng · libpng · CWE-125 | Yüksek7,1 | — | %0,4 | 24 Kas 2025 |
- CVE-2010-120552Planlayın
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attack
KritikCVSS 9,8Kavram kanıtıEPSS %43libpng · libpng30 Haz 2010
- CVE-2017-1265240Planlayın
libpng before 1.6.32 does not properly check the length of chunks against the user limit.
KritikCVSS 9,8İstismar yokEPSS %4libpng · libpng10 Tem 2019
- CVE-2015-854037İzleyin
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1
YüksekCVSS 8,8İstismar yokEPSS %6libpng · libpng14 Nis 2016
- CVE-2011-269236İzleyin
The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 do
YüksekCVSS 8,8İstismar yokEPSS %4libpng · libpng17 Tem 2011
- CVE-2015-097336İzleyin
Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent at
YüksekCVSS 8,8İstismar yokEPSS %4libpng · libpng18 Oca 2015
- CVE-2014-949536İzleyin
Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems,
YüksekCVSS 8,8Kavram kanıtıEPSS %4libpng · libpng10 Oca 2015
- CVE-2011-304536İzleyin
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.8
YüksekCVSS 8,8İstismar yokEPSS %4google · chrome22 Mar 2012
- CVE-2018-1455036İzleyin
An issue has been found in third-party PNM decoding associated with libpng 1.6.35.
YüksekCVSS 8,8İstismar yokEPSS %4libpng · libpng10 Tem 2019
- CVE-2011-269036İzleyin
Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application
YüksekCVSS 8,8İstismar yokEPSS %3libpng · libpng17 Tem 2011
- CVE-2015-812633İzleyin
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3
YüksekCVSS 7,5İstismar yokEPSS %10libpng · libpng12 Kas 2015
- CVE-2026-2564633İzleyin
LIBPNG has a heap buffer overflow in png_set_quantize
YüksekCVSS 8,3İstismar yokEPSS %1libpng · libpng10 Şub 2026
- CVE-2008-138232İzleyin
libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial
YüksekCVSS 7,5İstismar yokEPSS %6libpng · libpng14 Nis 2008
- CVE-2016-1008732İzleyin
The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.
YüksekCVSS 7,5İstismar yokEPSS %5libpng · libpng30 Oca 2017
- CVE-2015-847231İzleyin
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x befor
YüksekCVSS 7,3İstismar yokEPSS %6libpng · libpng21 Oca 2016
- CVE-2011-346431İzleyin
Off-by-one error in the png_formatted_warning function in pngerror.c in libpng 1.5.4 through 1.5.7 might allow remote attackers to cause a d
YüksekCVSS 7,5İstismar yokEPSS %3libpng · libpng22 Tem 2012
- CVE-2016-375131İzleyin
Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befo
YüksekCVSS 7,8İstismar yokEPSS %0libpng · libpng10 Tem 2016
- CVE-2020-3551131İzleyin
A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.
YüksekCVSS 7,8İstismar yokEPSS %0libpng · pngcheck23 Ağu 2022
- CVE-2026-2280131İzleyin
LIBPNG has an integer truncation causing heap buffer over-read in png_image_write_*
YüksekCVSS 7,8İstismar yokEPSS %0libpng · libpng12 Oca 2026
- CVE-2026-3341630İzleyin
LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`
YüksekCVSS 7,5İstismar yokEPSS %1libpng · libpng26 Mar 2026
- CVE-2026-3363630İzleyin
LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64
YüksekCVSS 7,6İstismar yokEPSS %0libpng · libpng26 Mar 2026
- CVE-2011-304829İzleyin
The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 all
OrtaCVSS 6,8İstismar yokEPSS %7libpng · libpng29 May 2012
- CVE-2011-040829İzleyin
pngrtran.c in libpng 1.5.x before 1.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitra
OrtaCVSS 6,8İstismar yokEPSS %6libpng · libpng18 Oca 2011
- CVE-2008-621829İzleyin
Memory leak in the png_handle_tEXt function in pngrutil.c in libpng before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers t
YüksekCVSS 7,1İstismar yokEPSS %2libpng · libpng20 Şub 2009
- CVE-2009-004028İzleyin
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-de
OrtaCVSS 6,8İstismar yokEPSS %5libpng · libpng22 Şub 2009
- CVE-2025-6472028İzleyin
LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication
YüksekCVSS 7,1Kavram kanıtıEPSS %0libpng · libpng24 Kas 2025