Libpng
libpng
59 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (59)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibpng+1 moreApr 29, 2026 Jul 17, 2011 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cau...Show more |
3Debian FedoraprojectLibpng3Debian Linux FedoraLibpngApr 29, 2026 Jul 17, 2011 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, w...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibpng+1 moreApr 29, 2026 Jul 17, 2011 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, all...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibpng+1 moreApr 29, 2026 Jul 17, 2011 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a c...Show more |
pngrtran.c in libpng 1.5.x before 1.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted palette-based PNG image that triggers a buffer overflow, r...Show more |
8Apple CanonicalDebian+5 more12Debian Linux FedoraIphone Os+9 moreApr 29, 2026 Jun 30, 2010 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Sca...Show more |
10Apple CanonicalDebian+7 more17Chrome Debian LinuxFedora+14 moreApr 29, 2026 Jun 30, 2010 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data r...Show more |
7Apple CanonicalDebian+4 more7Debian Linux FedoraLibpng+4 moreApr 29, 2026 Mar 3, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large unco...Show more |
libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote a...Show more |
6Apple DebianFedoraproject+3 more9Debian Linux FedoraIphone Os+6 moreApr 23, 2026 Feb 22, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly e...Show more |
Memory leak in the png_handle_tEXt function in pngrutil.c in libpng before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted PNG file. |
The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creati...Show more |
Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted z...Show more |
libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG file with zero...Show more |
Certain chunk handlers in libpng before 1.0.29 and 1.2.x before 1.2.21 allow remote attackers to cause a denial of service (crash) via crafted (1) pCAL (png_handle_pCAL), (2) sCAL (png_handle_sCAL), (3) tEXt (png_push_re...Show more |
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafte...Show more |
Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.2.22 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image, due to an incorr...Show more |
Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.0.29 beta1 and 1.2.x before 1.2.21 beta1 allows remote attackers to cause a denial of service (crash) via a craft...Show more |
4Libpng OpenpkgRedhat+1 more6Enterprise Linux Enterprise Linux DesktopLibpng+3 moreApr 16, 2026 Aug 18, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creatin...Show more |