CVE-2016-5735: Pngquant
High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow.
Affected products
- Pngquant Pngquant: version 2.7.0 only
Published 2017-05-23. Last modified 2026-06-17.