Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.36% | — | LibpngAI | 4/6/2026 | 22/7/2026 | LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an… | |
| Analizada | Media (4.4) | 0.16% | — | LibpngDebian Linux | 9/4/2026 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair… | |
| Analizada | Alta (7.6) | 0.36% | — | Libpng | 26/3/2026 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB… | |
| Analizada | Alta (7.5) | 1.1% | — | Libpng | 26/3/2026 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`, sharing a single allocation across two… | |
| Aplazada | Baja (1.9) | 0.18% | — | Pnggroup LibpngAI | 8/3/2026 | 17/6/2026 | A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit… | |
| Modificada | Alta (8.3) | 0.66% | — | Libpng | 10/2/2026 | 11/8/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the… | |
| Analizada | Media (5.5) | 0.16% | — | Libpng | 27/1/2026 | 17/6/2026 | Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function. | |
| Analizada | Media (5.5) | 0.16% | — | Libpng | 27/1/2026 | 17/6/2026 | Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive | |
| Analizada | Alta (7.8) | 0.13% | — | Libpng | 12/1/2026 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when… | |
| Analizada | Alta (7.1) | 0.22% | — | Libpng | 12/1/2026 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.51 to 1.6.53, there is a heap buffer over-read in the libpng simplified API function png_image_finish_read when processing interlaced 16-bit PNGs with 8-bit output format… | |
| Analizada | Alta (7.1) | 0.35% | — | Libpng | 3/12/2025 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette… | |
| Analizada | Alta (7.1) | 0.26% | — | Libpng | 25/11/2025 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the libpng simplified API function png_image_finish_read when processing 16-bit interlaced… | |
| Analizada | Alta (7.1) | 0.42% | — | Libpng | 25/11/2025 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled.… | |
| Analizada | Media (6.1) | 0.14% | — | Libpng | 25/11/2025 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_write_image_8bit function when processing 8-bit images through the simplified… | |
| Analizada | Media (6.1) | 0.19% | — | Libpng | 25/11/2025 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The… | |
| Modificada | Media (5.5) | 0.52% | — | LibpngDebian LinuxNetapp Ontap Select Deploy Administration Utility | 24/8/2022 | 17/6/2026 | A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service. | |
| Modificada | Alta (7.8) | 0.36% | — | Libpng PngcheckDebian Linux | 23/8/2022 | 17/6/2026 | A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file. | |
| Modificada | Baja (3.3) | 1.2% | — | Libpng PngcheckFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 8/12/2020 | 17/6/2026 | A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability. | |
| Modificada | Crítica (9.8) | 4.1% | — | LibpngNetapp Active IQ Unified Manager | 10/7/2019 | 17/6/2026 | libpng before 1.6.32 does not properly check the length of chunks against the user limit. | |
| Modificada | Alta (8.8) | 3.5% | — | LibpngOracle Hyperion Infrastructure TechnologyOracle Mysql WorkbenchNetapp Active IQ Unified Manager+1 | 10/7/2019 | 17/6/2026 | An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png. | |
| Modificada | Media (5.3) | 9.4% | — | LibpngDebian LinuxCanonical Ubuntu LinuxOracle Hyperion Infrastructure Technology+28 | 4/2/2019 | 17/6/2026 | png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute. | |
| Modificada | Media (6.5) | 1.6% | — | Libpng | 11/1/2019 | 17/6/2026 | png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer. | |
| Modificada | Media (6.5) | 3.3% | — | LibpngOracle JDKOracle JRE | 13/7/2018 | 17/6/2026 | An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image. | |
| Modificada | Media (6.5) | 4.4% | — | LibpngCanonical Ubuntu LinuxOracle JDKOracle JRE+3 | 9/7/2018 | 17/6/2026 | In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service. | |
| Modificada | Alta (7.5) | 5.1% | — | Libpng | 30/1/2017 | 17/6/2026 | The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure, removing the text, and then adding another… |