Skip to main content

Vendor/product archive

webmproject / libvpx CVEs

Beta · best-effort

6 CVEs tagged to webmproject / libvpx1 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-5197

Published Jun 3, 2024

There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflo…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6349

Published May 27, 2024

A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx.…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5217

Published Sep 28, 2023

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cr…

CVSS 8.8 · High
evidence mentions
21
Buzz score
69.5
KEV listed

CVE-2012-0823

Published Feb 23, 2012

VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting deco…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1