Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0

Affected products and versions

1 source assertion
{"product":"libpng","vendor":"pnggroup","versions":[{"status":"affected","version":">= 1.2.1, < 1.6.56"}]}
  • cve_program_cvelist_v5affected
    urn:baitaphish:normalized-source-record:v2:25cda484c5505bdb3e82134c70ce141b9652e1a8a03a27380853059d88078c91 · sha256:502059e02c11bed9… · /containers/cna/affected/0

Provider-owned CVSS observations

1 source assertion
{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
  • cve_program_cvelist_v5cvss
    urn:baitaphish:normalized-source-record:v2:25cda484c5505bdb3e82134c70ce141b9652e1a8a03a27380853059d88078c91 · sha256:502059e02c11bed9… · /containers/cna/metrics/0/cvssV3_1

CWE assertions

1 source assertion
{"cweId":"CWE-416","description":"CWE-416: Use After Free","lang":"en","type":"CWE"}
  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:25cda484c5505bdb3e82134c70ce141b9652e1a8a03a27380853059d88078c91 · sha256:502059e02c11bed9… · /containers/cna/problemTypes/0/descriptions/0

Source references

6 source assertions
{"name":"https://github.com/pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb","tags":["x_refsource_MISC"],"url":"https://github.com/pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:25cda484c5505bdb3e82134c70ce141b9652e1a8a03a27380853059d88078c91 · sha256:502059e02c11bed9… · /containers/cna/references/2
{"name":"https://github.com/pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667","tags":["x_refsource_MISC"],"url":"https://github.com/pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:25cda484c5505bdb3e82134c70ce141b9652e1a8a03a27380853059d88078c91 · sha256:502059e02c11bed9… · /containers/cna/references/3
{"name":"https://github.com/pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25","tags":["x_refsource_MISC"],"url":"https://github.com/pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:25cda484c5505bdb3e82134c70ce141b9652e1a8a03a27380853059d88078c91 · sha256:502059e02c11bed9… · /containers/cna/references/4
{"name":"https://github.com/pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1","tags":["x_refsource_MISC"],"url":"https://github.com/pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:25cda484c5505bdb3e82134c70ce141b9652e1a8a03a27380853059d88078c91 · sha256:502059e02c11bed9… · /containers/cna/references/5
{"name":"https://github.com/pnggroup/libpng/pull/824","tags":["x_refsource_MISC"],"url":"https://github.com/pnggroup/libpng/pull/824"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:25cda484c5505bdb3e82134c70ce141b9652e1a8a03a27380853059d88078c91 · sha256:502059e02c11bed9… · /containers/cna/references/1
{"name":"https://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j","tags":["x_refsource_CONFIRM"],"url":"https://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:25cda484c5505bdb3e82134c70ce141b9652e1a8a03a27380853059d88078c91 · sha256:502059e02c11bed9… · /containers/cna/references/0

Attribution and limitations

  • CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →

Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.