Skip to main content

Vendor archive

webmproject CVEs

Beta · best-effort

25 CVEs tagged to vendor webmproject12 Critical, 7 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2024-5197

Published Jun 3, 2024

There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflo…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6349

Published May 27, 2024

A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx.…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5217

Published Sep 28, 2023

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cr…

CVSS 8.8 · High
evidence mentions
21
Buzz score
69.5
KEV listed

CVE-2023-4863

Published Sep 12, 2023

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pa…

CVSS 8.8 · High
evidence mentions
30
Buzz score
72.5
KEV listed

CVE-2023-1999

Published Jun 20, 2023

There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. Th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9746

Published Mar 13, 2019

In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger an abort, which allows a DoS attack, a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19212

Published Nov 12, 2018

In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6548

Published Feb 2, 2018

A use-after-free issue was discovered in libwebm through 2018-02-02. If a Vp9HeaderParser was initialized once before, its property frame_ would not be changed because of code in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6406

Published Jan 30, 2018

The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data obtained from a .webm file, which allows…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0823

Published Feb 23, 2012

VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting deco…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1