CVE-2016-10087 describes a NULL pointer dereference vulnerability in multiple versions of the libpng library (0.71 to 1.6.27). This flaw occurs when specific text chunk manipulation operations are performed on a PNG structure, potentially leading to a denial of service. With a CVSS v3 score of 7.5 (High), this vulnerability is remotely exploitable with low attack complexity and no user interaction required, resulting in high availability impact. While there is no known exploit intelligence (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:0.8:*:*:*:*:*:*:* | ||
0.71CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:0.71:*:*:*:*:*:*:* | ||
0.81CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:0.81:*:*:*:*:*:*:* | ||
0.82CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:0.82:*:*:*:*:*:*:* | ||
0.85CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:0.85:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.