CVE-2016-5735: Pngquant

High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow.

Affected products

Published 2017-05-23. Last modified 2026-06-17.