CVE-2015-0973: Apple Mac OS X
High severity, CVSS 8.8. EPSS: 4.1% chance of exploitation in the next 30 days.
Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.
Affected products
- Apple Mac OS X: up to and including 10.11.3
- Libpng Libpng: up to and including 1.5.20; version 1.6.0 only; version 1.6.1 only; version 1.6.2 only; version 1.6.3 only; version 1.6.4 only; …
- Oracle Solaris: version 11.2 only
Published 2015-01-18. Last modified 2026-06-17.