CVE-2014-9495: Apple Mac OS X
High severity, CVSS 8.8. EPSS: 4.1% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers to execute arbitrary code via a "very wide interlaced" PNG image.
Affected products
- Apple Mac OS X: up to and including 10.11.3
- Libpng Libpng: up to and including 1.5.20; version 1.6.0 only; version 1.6.1 only; version 1.6.2 only; version 1.6.3 only; version 1.6.4 only; …
Published 2015-01-10. Last modified 2026-06-17.