Skip to main content

Vendor/product archive

xiph.org / libvorbis CVEs

Beta · best-effort

13 CVEs tagged to xiph.org / libvorbis2 Critical, 3 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2020-20412

Published Dec 26, 2020

lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14160

Published Sep 21, 2017

The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11333

Published Jul 31, 2017

The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2009

Published May 16, 2008

Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4065

Published Sep 21, 2007

lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka tr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4066

Published Sep 21, 2007

Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unspecified impact via a crafted OGG file…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1