CVE-2005-2096

zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.

Scoring

CVSS base score
7.5
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS probability
43.03%
Published
2005-07-06
Last modified
2026-07-14

Affected products

Markdown version · Browse all CVEs