Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Fedora 42 and 43 have identified critical vulnerabilities in the libpng package, which is essential for handling PNG image files. The vulnerabilities include a buffer overflow and a high-severity out-of-bounds read (CVE-2025-66293) in png_image_read_composite, necessitating immediate updates for aff...
openSUSE has released an update for libpng16 to address multiple vulnerabilities, including heap buffer overflows and out-of-bounds reads. The vulnerabilities, identified as CVE-2025-65018, CVE-2025-66293, CVE-2025-64506, and CVE-2025-64720, could potentially lead to security risks for users of the...
Oracle has released ELSA-2026-0241 to address multiple vulnerabilities in libpng, affecting versions 1.6.34-9 and earlier. Key issues include a buffer overflow (CVE-2025-64720), a heap buffer overflow (CVE-2025-65018), and an out-of-bounds read (CVE-2025-66293). Users are advised to update to the la...
Vulnerabilities in the libpng simplified API were discovered, affecting the processing of palette PNG images with partial transparency and gamma correction. If exploited, an attacker could cause libpng to crash, resulting in a denial of service for users or automated systems. The issues were identif...