Количество 13
Количество 13
CVE-2025-64505
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.
CVE-2025-64505
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.
CVE-2025-64505
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.
CVE-2025-64505
LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index
CVE-2025-64505
LIBPNG is a reference library for use in applications that read, creat ...
SUSE-SU-2026:0898-1
Security update for libpng15
SUSE-SU-2025:4432-1
Security update for libpng12
SUSE-SU-2025:4383-1
Security update for libpng12
BDU:2026-02923
Уязвимость функции png_do_quantize() компонента pngrtran.c библиотеки для работы с растровой графикой в формате PNG Libpng, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
SUSE-SU-2025:4533-1
Security update for libpng16
openSUSE-SU-2026:20017-1
Security update for libpng16
SUSE-SU-2025:4494-1
Security update for libpng16
SUSE-SU-2025:4436-1
Security update for libpng16
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-64505 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51. | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
CVE-2025-64505 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51. | CVSS3: 4.4 | 0% Низкий | 4 месяца назад | |
CVE-2025-64505 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51. | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
CVE-2025-64505 LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
CVE-2025-64505 LIBPNG is a reference library for use in applications that read, creat ... | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
SUSE-SU-2026:0898-1 Security update for libpng15 | 0% Низкий | 17 дней назад | ||
SUSE-SU-2025:4432-1 Security update for libpng12 | 0% Низкий | 3 месяца назад | ||
SUSE-SU-2025:4383-1 Security update for libpng12 | 0% Низкий | 4 месяца назад | ||
BDU:2026-02923 Уязвимость функции png_do_quantize() компонента pngrtran.c библиотеки для работы с растровой графикой в формате PNG Libpng, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании | CVSS3: 6.1 | 0% Низкий | 10 месяцев назад | |
SUSE-SU-2025:4533-1 Security update for libpng16 | 3 месяца назад | |||
openSUSE-SU-2026:20017-1 Security update for libpng16 | 3 месяца назад | |||
SUSE-SU-2025:4494-1 Security update for libpng16 | 3 месяца назад | |||
SUSE-SU-2025:4436-1 Security update for libpng16 | 3 месяца назад |
Уязвимостей на страницу