Логотип exploitDog
bind:"CVE-2010-0205" OR bind:"CVE-2009-2042" OR bind:"CVE-2010-1205" OR bind:"CVE-2010-2249"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2010-0205" OR bind:"CVE-2009-2042" OR bind:"CVE-2010-1205" OR bind:"CVE-2010-2249"

Количество 25

Количество 25

oracle-oval логотип

ELSA-2010-0534

почти 15 лет назад

ELSA-2010-0534: libpng security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2015-09413

больше 14 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2010-0205

больше 15 лет назад

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2010-0205

больше 15 лет назад

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-0205

больше 15 лет назад

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-0205

больше 15 лет назад

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-qjvj-64rf-p4qg

около 3 лет назад

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.

EPSS: Низкий
ubuntu логотип

CVE-2009-2042

около 16 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2009-2042

около 16 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2009-2042

около 16 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-2042

около 16 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images w ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-rh45-m734-j52q

около 3 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

EPSS: Низкий
fstec логотип

BDU:2015-09396

почти 16 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-2249

почти 15 лет назад

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2010-2249

почти 15 лет назад

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2249

почти 15 лет назад

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2010-2249

почти 15 лет назад

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1. ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2010-1205

почти 15 лет назад

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2010-1205

почти 15 лет назад

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2010-1205

почти 15 лет назад

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2010-0534

ELSA-2010-0534: libpng security update (IMPORTANT)

почти 15 лет назад
fstec логотип
BDU:2015-09413

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 7.8
больше 14 лет назад
ubuntu логотип
CVE-2010-0205

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.

CVSS2: 4.3
8%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-0205

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.

CVSS2: 4.3
8%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-0205

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.

CVSS2: 4.3
8%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-0205

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before ...

CVSS2: 4.3
8%
Низкий
больше 15 лет назад
github логотип
GHSA-qjvj-64rf-p4qg

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.

8%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2009-2042

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

CVSS2: 4.3
3%
Низкий
около 16 лет назад
redhat логотип
CVE-2009-2042

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

CVSS2: 2.6
3%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-2042

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

CVSS2: 4.3
3%
Низкий
около 16 лет назад
debian логотип
CVE-2009-2042

libpng before 1.2.37 does not properly parse 1-bit interlaced images w ...

CVSS2: 4.3
3%
Низкий
около 16 лет назад
github логотип
GHSA-rh45-m734-j52q

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

3%
Низкий
около 3 лет назад
fstec логотип
BDU:2015-09396

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

CVSS2: 4.3
3%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-2249

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

CVSS3: 6.5
2%
Низкий
почти 15 лет назад
redhat логотип
CVE-2010-2249

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-2249

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

CVSS3: 6.5
2%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-2249

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1. ...

CVSS3: 6.5
2%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-1205

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVSS3: 9.8
17%
Средний
почти 15 лет назад
redhat логотип
CVE-2010-1205

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVSS2: 6.8
17%
Средний
почти 15 лет назад
nvd логотип
CVE-2010-1205

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVSS3: 9.8
17%
Средний
почти 15 лет назад

Уязвимостей на страницу