Pngcrush is a specialized utility for PNG image compression and optimization with a focused vulnerability footprint centered on the compression tool itself. The observed exposure reflects memory-management issues, specifically double-free conditions, that can arise in image-parsing codebases. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pngcrush Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7700CRITICAL Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors. | Aug 31, 2017 | 9.8 | 24 | NO | NO |
CVE-2015-2158HIGH Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly | Oct 6, 2017 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pngcrush Project.
Media articles that mention a CVE ID that affects a product developed by Pngcrush Project — matched by CVE ID, not by vendor name.