png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
Conclusion & alert: CVE-2019-7317 is rated High Exploit Risk (74.4/100): CVSS Medium severity, with high exploitation likelihood (EPSS 9.39%, 95th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +8.83% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.56% | 9.39% | +8.83% |
| 2 | 2025-12-28 | 0.42% | 0.56% | +0.14% |
| 3 | 2025-12-27 | — | 0.42% | — |
Full EPSS history (29 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
1.6 | 3.6 | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
1.6 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 2.6 | 2.0 | LOW |
|
4.9 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
medium | CVE-2019-7317: 4 source package rows (firefox-esr, libpng, openjdk11, openjdk8); 31 state rows across 17 repos (3.10-main, 3.11-main, 3.12-main, 3.17-community, 3.17-main, 3.18-community, 3.18-main, 3.19-community, 3.19-main, 3.20-community, 3.20-main, 3.21-community, 3.21-main, 3.22-community, 3.22-main, edge-community, edge-main); fixed 31, open 0. | https://security.alpinelinux.org/vuln/CVE-2019-7317 |
debian
|
not yet assigned | CVE-2019-7317 not yet assigned priority: Debian including 4 source packages (firefox, firefox-esr, libpng1.6, thunderbird), 16 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 16. | https://security-tracker.debian.org/tracker/CVE-2019-7317 |
gentoo
|
normal | CVE-2019-7317: 1 GLSA(s) (201908-02), 1 atom(s) (media-libs/libpng); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2019-7317 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2019-7317 |
suse
|
medium | CVE-2019-7317 severity moderate: SUSE including 504 source package names (0.38.1:libpng16-16-1.6.34-3.9.1, 0.45.0.7.7.1:libpng16-16-1.6.34-3.9.1, …), 1523 product×package rows across 346 product lines (Container bci/openjdk, Container bci/openjdk-devel, … (346 product lines)): Fixed 1360, Known Affected 157, Known Not Affected 6. | https://www.suse.com/security/cve/CVE-2019-7317/ |
ubuntu
|
medium | CVE-2019-7317 medium priority: Ubuntu including 8 source packages (firefox, libpng, …), 148 status rows across 19 suites (bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 54, released 44, not-affected 42, needs-triage 5, ignored 2, needed 1. | https://ubuntu.com/security/CVE-2019-7317 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| libpng | libpng | >= 1.6.0, < 1.6.37 | cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* |
| canonical | ubuntu_linux | 18.04 | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 18.10 | cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 19.04 | cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:* |
| oracle | hyperion_infrastructure_technology | 11.2.6.0 | cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.6.0:*:*:*:*:*:*:* |
| oracle | java_se | 7u221 | cpe:2.3:a:oracle:java_se:7u221:*:*:*:*:*:*:* |
| oracle | java_se | 8u212 | cpe:2.3:a:oracle:java_se:8u212:*:*:*:*:*:*:* |
| oracle | jdk | 11.0.3 | cpe:2.3:a:oracle:jdk:11.0.3:*:*:*:*:*:*:* |
| oracle | jdk | 12.0.1 | cpe:2.3:a:oracle:jdk:12.0.1:*:*:*:*:*:*:* |
| oracle | mysql | < 8.0.23 | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* |
| hp | xp7_command_view | < 8.7.0-00 | cpe:2.3:a:hp:xp7_command_view:*:*:*:*:advanced:*:*:* |
| hpe | xp7_command_view_advanced_edition_suite | < 8.7.0-00 | cpe:2.3:a:hpe:xp7_command_view_advanced_edition_suite:*:*:*:*:*:*:*:* |
| mozilla | firefox | — | cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:* |
| mozilla | thunderbird | — | cpe:2.3:a:mozilla:thunderbird:-:*:*:*:*:*:*:* |
| opensuse | leap | 15.0 | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* |
| opensuse | leap | 15.1 | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
| opensuse | leap | 42.3 | cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:* |
| opensuse | package_hub | — | cpe:2.3:a:opensuse:package_hub:-:*:*:*:*:*:*:* |
| netapp | active_iq_unified_manager | < 9.6 | cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:* |
| netapp | active_iq_unified_manager | < 9.6 | cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:* |
| netapp | active_iq_unified_manager | 9.6 | cpe:2.3:a:netapp:active_iq_unified_manager:9.6:*:*:*:*:vmware_vsphere:*:* |
| netapp | active_iq_unified_manager | 9.6 | cpe:2.3:a:netapp:active_iq_unified_manager:9.6:*:*:*:*:windows:*:* |
| netapp | cloud_backup | — | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* |
| netapp | e-series_santricity_management | — | cpe:2.3:a:netapp:e-series_santricity_management:-:*:*:*:*:vcenter:*:* |
| netapp | e-series_santricity_storage_manager | < 11.53 | cpe:2.3:a:netapp:e-series_santricity_storage_manager:*:*:*:*:*:*:*:* |
| netapp | e-series_santricity_unified_manager | < 3.2 | cpe:2.3:a:netapp:e-series_santricity_unified_manager:*:*:*:*:*:*:*:* |
| netapp | e-series_santricity_web_services | < 4.0 | cpe:2.3:a:netapp:e-series_santricity_web_services:*:*:*:*:*:web_services_proxy:*:* |
| netapp | oncommand_insight | < 7.3.9 | cpe:2.3:a:netapp:oncommand_insight:*:*:*:*:*:*:*:* |
| netapp | oncommand_workflow_automation | < 5.1 | cpe:2.3:a:netapp:oncommand_workflow_automation:*:*:*:*:*:*:*:* |
| netapp | plug-in_for_symantec_netbackup | — | cpe:2.3:a:netapp:plug-in_for_symantec_netbackup:-:*:*:*:*:*:*:* |
| netapp | snapmanager | < 3.4.2 | cpe:2.3:a:netapp:snapmanager:*:*:*:*:*:oracle:*:* |
| netapp | snapmanager | < 3.4.2 | cpe:2.3:a:netapp:snapmanager:*:*:*:*:*:sap:*:* |
| netapp | snapmanager | 3.4.2 | cpe:2.3:a:netapp:snapmanager:3.4.2:p1:*:*:*:oracle:*:* |
| netapp | snapmanager | 3.4.2 | cpe:2.3:a:netapp:snapmanager:3.4.2:p1:*:*:*:sap:*:* |
| netapp | steelstore | — | cpe:2.3:a:netapp:steelstore:-:*:*:*:*:*:*:* |
| redhat | satellite | 5.8 | cpe:2.3:a:redhat:satellite:5.8:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 6.0 | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 7.0 | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_desktop | 6.0 | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_desktop | 7.0 | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 6.0 | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 7.0 | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 8.0 | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_big_endian | 6.0 | cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_big_endian | 7.0 | cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian | 7.0 | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian | 8.0 | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_scientific_computing | 6.0 | cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:6.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_scientific_computing | 7.0 | cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_workstation | 6.0 | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_workstation | 7.0 | cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:* |