Pngdec Project maintains a focused PNG image-decoding library that, despite its narrow scope, sees embedded use across a range of image-processing applications and platforms where it handles untrusted image data. The recurring weakness classes—out-of-bounds writes, buffer overflows, uncontrolled resource consumption, and memory-allocation issues—reflect the parsing complexity and memory-safety challenges inherent to decoding image file formats. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pngdec Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35011HIGH PNGDec commit 8abf6be was discovered to contain a global buffer overflow via inflate_fast at /src/inffast.c. | Aug 16, 2022 | 8.8 | 26 | NO | NO |
CVE-2022-35013MEDIUM PNGDec commit 8abf6be was discovered to contain a FPE via SaveBMP at /linux/main.cpp. | Aug 16, 2022 | 6.5 | 21 | NO | NO |
CVE-2022-35012MEDIUM PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via SaveBMP at /linux/main.cpp. | Aug 16, 2022 | 6.5 | 21 | NO | NO |
CVE-2022-35010MEDIUM PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via asan_interceptors_memintrinsics.cpp. | Aug 16, 2022 | 6.5 | 21 | NO | NO |
CVE-2022-35009MEDIUM PNGDec commit 8abf6be was discovered to contain a memory allocation problem via asan_malloc_linux.cpp. | Aug 16, 2022 | 6.5 | 21 | NO | NO |
CVE-2022-35008MEDIUM PNGDec commit 8abf6be was discovered to contain a stack overflow via /linux/main.cpp. | Aug 16, 2022 | 6.5 | 21 | NO | NO |
CVE-2022-35007MEDIUM PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via __interceptor_fwrite.part.57 at sanitizer_common_interceptors.inc. | Aug 16, 2022 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pngdec Project.
Media articles that mention a CVE ID that affects a product developed by Pngdec Project — matched by CVE ID, not by vendor name.