← All CVEs

CVE-2004-0597

high · 10

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

10
CVSS
82.5%
EPSS (exploit prob.)
100th
EPSS percentile
2004-11-23
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
greg_roelofslibpng<= 1.2.5
microsoftmsn_messenger6.1
microsoftmsn_messenger6.2
microsoftwindows_media_player9
microsoftwindows_messenger5.0
microsoftwindows_98seall versions
microsoftwindows_meall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-0597