Vulnerabilities > Libpng > Libpng > 1.5.30

DATE CVE VULNERABILITY TITLE RISK
2019-07-10 CVE-2017-12652 Improper Input Validation vulnerability in multiple products
libpng before 1.6.32 does not properly check the length of chunks against the user limit.
network
low complexity
libpng netapp CWE-20
critical
9.8
2016-07-11 CVE-2016-3751 Remote Privilege Escalation vulnerability in Libpng
Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23265085.
network
low complexity
libpng google
7.5
2014-01-12 CVE-2013-6954 Denial of Service vulnerability in libpng 'png_read_transform_info()' Function NULL Pointer Dereference
The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c and pngset.c.
network
low complexity
libpng
5.0