Vulnerabilities > Pngcrush Project

DATE CVE VULNERABILITY TITLE RISK
2017-10-06 CVE-2015-2158 Numeric Errors vulnerability in Pngcrush Project Pngcrush
Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.
local
low complexity
pngcrush-project CWE-189
7.8
2017-08-31 CVE-2015-7700 Double Free vulnerability in Pngcrush Project Pngcrush
Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.
network
low complexity
pngcrush-project CWE-415
critical
9.8