cbcvebase.
CVE-2010-1205
published 2010-06-30

CVE-2010-1205: Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
appleiphone_os2.0 – 4.1
appleitunes< 10.210.2
applemac_os_x>= 10.6.0 < 10.6.410.6.4
applemac_os_x_server>= 10.6.0 < 10.6.410.6.4
applesafari< 5.0.45.0.4
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiantuxonice-userui< tuxonice-userui 1.0-1 (bookworm)tuxonice-userui 1.0-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
googlechrome< 5.0.375.995.0.375.99
libpnglibpng< 1.2.441.2.44
libpnglibpng>= 1.4.0 < 1.4.31.4.3
mozillafirefox< 3.5.113.5.11
mozillafirefox>= 3.5.12 < 3.6.73.6.7
mozillaseamonkey< 2.0.62.0.6
mozillathunderbird< 3.0.63.0.6
mozillathunderbird>= 3.0.7 < 3.1.13.1.1
opensuseopensuse
opensuseopensuse
suselinux_enterprise_server

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL