← Vulnerability feed

Vulnerability record · CVE-2016-10166 · published 15 March 2017

CVE-2016-10166: Libgd vulnerability

Libgd · Libgd

Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.

9.8 CVSS 3.0 Critical EPSS 11% · top 4.3% CWE-191 · CWE-191
9.8CVSS 3.0 base score, v2 7.5
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-10166 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-6978Libgd double free vulnerabilityThe GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is un…EPSS 4.5%9.8CVE-2016-6912Libgd double free vulnerabilityDouble free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecifi…EPSS 4.5%9.8CVE-2016-8670Libgd memory buffer overflow vulnerabilityInteger signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.…EPSS 4.8%9.8CVE-2016-7568Libgd integer overflow vulnerabilityInteger overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, all…EPSS 5.1%9.8CVE-2016-3074Libgd vulnerabilityInteger signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potential…EPSS 37%9.1CVE-2016-5116Libgd memory buffer overflow vulnerabilitygd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers …EPSS 3.8%8.8CVE-2019-6977LibGD gdImageColorMatch heap buffer overflow via PHP imagecolormatchgdImageColorMatch in LibGD 2.2.5, reached through PHP's imagecolormatch function, contains a heap-based buffer overflow (CWE-787 out-of-bounds write)…EPSS 71%analysed8.8CVE-2018-1000222Libgd double free vulnerabilityLibgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This atta…EPSS 4.2%

Source: NIST National Vulnerability Database (record CVE-2016-10166), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.