Ubuntu Security Notice USN-384-2 points out a vulnerability in libjpeg that could allow execution of arbitrary code through specially designed JPEG images.
Tavis Ormandy discovered that libpng did not correctly calculate the size of sPLT structures when reading an image