The Lupng Project maintains a specialized PNG parsing library whose vulnerabilities, though limited in volume, center on memory-access safety issues such as out-of-bounds reads and writes within the image-processing pipeline. This niche component's exposure pattern reflects the parsing complexity inherent to image format handling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lupng Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18583HIGH An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c during a write operation for data obtained from a swap. | Oct 22, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-18582HIGH An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c during a write operation for data obtained from a palette. | Oct 22, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-18581HIGH An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer over-read in internalPrintf in miniz/lupng.c. | Oct 22, 2018 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lupng Project.
Media articles that mention a CVE ID that affects a product developed by Lupng Project — matched by CVE ID, not by vendor name.