Vulnerabilities
Vulnerable Software
Libpng:  >> Libpng  >> 1.6.20  Security Vulnerabilities
libpng before 1.6.32 does not properly check the length of chunks against the user limit.
CVSS Score
9.8
EPSS Score
0.006
Published
2019-07-10
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
CVSS Score
5.3
EPSS Score
0.004
Published
2019-02-04
The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure, removing the text, and then adding another text chunk to the structure.
CVSS Score
7.5
EPSS Score
0.019
Published
2017-01-30


Contact Us

Shodan ® - All rights reserved