CVE-2016-10087: Libpng
High severity, CVSS 7.5. EPSS: 5.1% chance of exploitation in the next 30 days.
The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure, removing the text, and then adding another text chunk to the structure.
Affected products
- Libpng Libpng: version 0.8 only; version 0.71 only; version 0.81 only; version 0.82 only; version 0.85 only; version 0.86 only; …
Published 2017-01-30. Last modified 2026-06-17.