peter bassill · operator
$ cve CVE-2010-1205 JSON

CVE-2010-1205 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 43.4% (pctl 99)

Patch early

A public exploit exists.

Description

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS43.38% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploityes
Published2010-06-30
Last modified2026-06-16

Affected (17)

VendorProduct
appleiphone os
appleitunes
applemac os x
applemac os x server
applesafari
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
googlechrome
libpnglibpng
mozillafirefox
mozillaseamonkey
mozillathunderbird
opensuseopensuse
suselinux enterprise server
vmwareplayer
vmwareworkstation

Public exploits

SourceTitleDate
exploit-dblibpng 1.4.2 - Denial of Service2010-07-20

References

→ the Explorer  ·  watch your stack  ·  NVD