Greg Roelofs's vulnerability profile centers on libpng and related image-processing utilities, widely embedded in applications and libraries that handle PNG image parsing and conversion. The recurring exposure pattern involves memory-safety and input-validation issues inherent to image format parsing, with vulnerabilities tending to acquire public exploit code. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Greg Roelofs over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0597HIGH Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_ | Nov 23, 2004 | 10.0 | 81 | NO | YES |
CVE-2002-0660HIGH Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and | Aug 12, 2002 | 7.5 | 25 | NO | NO |
CVE-2002-1363HIGH Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possib | Dec 26, 2002 | 7.5 | 21 | NO | NO |
CVE-2006-3334HIGH Buffer overflow in the png_decompress_chunk function in pngrutil.c in libpng before 1.2.12 allows context-dependent attackers to cause a denial of service and possibly execute arbi | Jun 30, 2006 | 7.5 | 20 | NO | NO |
CVE-2004-0768HIGH libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack. | Oct 20, 2004 | 7.5 | 20 | NO | NO |
CVE-2004-0598MEDIUM The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null deref | Nov 23, 2004 | 5.0 | 17 | NO | NO |
CVE-2004-0599MEDIUM Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 a | Nov 23, 2004 | 5.0 | 17 | NO | NO |
The png_handle_cHRM function in pngrutil.c in libpng 1.5.4, when color-correction support is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and | Jan 17, 2012 | 2.6 | 16 | NO | NO |
CVE-2006-0481MEDIUM Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler functi | Jan 31, 2006 | 5.0 | 16 | NO | NO |
CVE-2002-0728MEDIUM Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that h | Aug 12, 2002 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Greg Roelofs.
Media articles that mention a CVE ID that affects a product developed by Greg Roelofs — matched by CVE ID, not by vendor name.