Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 35

Количество 35

ubuntu логотип

CVE-2026-33636

4 месяца назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2026-33636

4 месяца назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-33636

4 месяца назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.

CVSS3: 7.6
EPSS: Низкий
msrc логотип

CVE-2026-33636

4 месяца назад

LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2026-33636

4 месяца назад

LIBPNG is a reference library for use in applications that read, creat ...

CVSS3: 7.6
EPSS: Низкий
rocky логотип

RLSA-2026:14791

3 месяца назад

Moderate: libpng security update

EPSS: Низкий
rocky логотип

RLSA-2026:14790

3 месяца назад

Moderate: libpng security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-14791

3 месяца назад

ELSA-2026-14791: libpng security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-14790

3 месяца назад

ELSA-2026-14790: libpng security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2026-06669

4 месяца назад

Уязвимость библиотеки libpng, связанная с отсутствием проверки достаточного количества входных пикселей, позволяющая нарушителю раскрыть защищаемую информации и выполнить отказ в обслуживании

CVSS3: 7.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20466-1

4 месяца назад

Security update for libpng16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1368-1

4 месяца назад

Security update for libpng16

EPSS: Низкий
redos логотип

ROS-20260526-73-0021

2 месяца назад

Уязвимость libpng12

CVSS3: 7.6
EPSS: Низкий
redos логотип

ROS-20260526-73-0020

2 месяца назад

Уязвимость libpng

CVSS3: 7.6
EPSS: Низкий
redos логотип

ROS-20260526-73-0019

2 месяца назад

Уязвимость mingw-libpng

CVSS3: 7.6
EPSS: Низкий
redos логотип

ROS-20260526-73-0018

2 месяца назад

Уязвимость libpng15

CVSS3: 7.6
EPSS: Низкий
rocky логотип

RLSA-2026:28255

около 1 месяца назад

Moderate: libpng security update

EPSS: Низкий
rocky логотип

RLSA-2026:28233

около 1 месяца назад

Moderate: libpng security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-28255

около 1 месяца назад

ELSA-2026-28255: libpng security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-28233

15 дней назад

ELSA-2026-28233: libpng security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33636

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.

CVSS3: 7.6
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33636

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.

CVSS3: 7.6
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33636

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.

CVSS3: 7.6
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-33636

LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64

CVSS3: 7.6
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-33636

LIBPNG is a reference library for use in applications that read, creat ...

CVSS3: 7.6
1%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:14791

Moderate: libpng security update

1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:14790

Moderate: libpng security update

1%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-14791

ELSA-2026-14791: libpng security update (MODERATE)

3 месяца назад
oracle-oval логотип
ELSA-2026-14790

ELSA-2026-14790: libpng security update (MODERATE)

3 месяца назад
fstec логотип
BDU:2026-06669

Уязвимость библиотеки libpng, связанная с отсутствием проверки достаточного количества входных пикселей, позволяющая нарушителю раскрыть защищаемую информации и выполнить отказ в обслуживании

CVSS3: 7.6
1%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20466-1

Security update for libpng16

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1368-1

Security update for libpng16

4 месяца назад
redos логотип
ROS-20260526-73-0021

Уязвимость libpng12

CVSS3: 7.6
1%
Низкий
2 месяца назад
redos логотип
ROS-20260526-73-0020

Уязвимость libpng

CVSS3: 7.6
1%
Низкий
2 месяца назад
redos логотип
ROS-20260526-73-0019

Уязвимость mingw-libpng

CVSS3: 7.6
1%
Низкий
2 месяца назад
redos логотип
ROS-20260526-73-0018

Уязвимость libpng15

CVSS3: 7.6
1%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:28255

Moderate: libpng security update

около 1 месяца назад
rocky логотип
RLSA-2026:28233

Moderate: libpng security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-28255

ELSA-2026-28255: libpng security update (MODERATE)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-28233

ELSA-2026-28233: libpng security update (MODERATE)

15 дней назад

Уязвимостей на страницу