Search CVE reports


Toggle filters

41 – 50 of 62 results


CVE-2010-0205

Medium priority

Some fixes available 5 of 7

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed...

2 affected packages

firefox, libpng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
libpng
Show less packages

CVE-2009-2042

Low priority

Some fixes available 8 of 21

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers...

7 affected packages

libpng, mozilla-thunderbird, seamonkey, thunderbird, xulrunner...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 7 packages Show less packages

CVE-2009-0040

Medium priority

Some fixes available 15 of 31

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute...

12 affected packages

icedove, firefox, firefox-3.0, firefox-3.5, iceape...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icedove
firefox
firefox-3.0
firefox-3.5
iceape
libpng
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 12 packages Show less packages

CVE-2008-6218

Low priority
Not affected

Memory leak in the png_handle_tEXt function in pngrutil.c in libpng before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted PNG file.

1 affected package

libpng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng
Show less packages

CVE-2008-5907

Low priority
Fixed

The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creation of...

1 affected package

libpng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng
Show less packages

CVE-2008-3964

Low priority

Some fixes available 4 of 5

Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted...

1 affected package

libpng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng
Show less packages

CVE-2008-1382

Low priority

Some fixes available 3 of 5

libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG file with zero...

1 affected package

libpng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng
Show less packages

CVE-2007-5268

Negligible priority
Fixed

pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.

1 affected package

libpng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng
Show less packages

CVE-2007-5267

Medium priority
Not affected

Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.2.22 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image, due to an incorrect fix...

1 affected package

libpng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng
Show less packages

CVE-2007-5266

Medium priority
Not affected

Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.0.29 beta1 and 1.2.x before 1.2.21 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG...

1 affected package

libpng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng
Show less packages