Back

CVE-2016-6912

CRITICAL

Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.

Published: Jan 26, 2017 Modified: Jun 17, 2026
CWE-415

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
libgd libgd *

GitHub Security Advisory GHSA-wmff-45hx-q83q

Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd)...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 4.45%

Top 9% most likely to be exploited

Threat Score 40.5 / 100

Data Sources

NVD EPSS GitHub