CVE-2015-7700
CRITICALpngcrush <1.7.87 - Memory Corruption
Title source: llmDescription
Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.
Scores
CVSS v3
9.8
EPSS
0.0069
EPSS Percentile
71.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-415
Status
draft
Affected Products (1)
pngcrush_project/pngcrush
< 1.7.86
Timeline
Published
Aug 31, 2017
Tracked Since
Feb 18, 2026