← All CVEs

CVE-2010-1205

critical · 9.8

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

9.8
CVSS
43.4%
EPSS (exploit prob.)
99th
EPSS percentile
2010-06-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-120

Affected products

VendorProductAffected versions
libpnglibpng< 1.2.44
libpnglibpng>= 1.4.0, < 1.4.3
googlechrome< 5.0.375.99
appleitunes< 10.2
applesafari< 5.0.4
appleiphone_os>= 2.0, <= 4.1
applemac_os_x>= 10.6.0, < 10.6.4
applemac_os_x_server>= 10.6.0, < 10.6.4
fedoraprojectfedora12
fedoraprojectfedora13
opensuseopensuse11.1
opensuseopensuse11.2
suselinux_enterprise_server9
suselinux_enterprise_server10
suselinux_enterprise_server11
suselinux_enterprise_server11
vmwareplayer>= 2.5, < 2.5.5
vmwareplayer>= 3.1, < 3.1.2
vmwareworkstation>= 6.5.0, < 6.5.5
vmwareworkstation>= 7.1, < 7.1.2
canonicalubuntu_linux6.06
canonicalubuntu_linux8.04
canonicalubuntu_linux9.04
canonicalubuntu_linux9.10
canonicalubuntu_linux10.04
debiandebian_linux5.0
mozillafirefox< 3.5.11
mozillafirefox>= 3.5.12, < 3.6.7
mozillaseamonkey< 2.0.6
mozillathunderbird< 3.0.6
mozillathunderbird>= 3.0.7, < 3.1.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-1205