← Back

Libebml

libebml

Vendor: Matroska • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Matroska
1Libebml
Nov 4, 2025
Jan 12, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when reading or writing. It may result in buffer overflows.
3Debian
FedoraprojectMatroska
3Debian Linux
FedoraLibebml
Nov 21, 2024
Feb 23, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml.
1Matroska
1Libebml
May 6, 2026
Jan 29, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an...Show more
The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an invalid memory access.Show less
1Matroska
1Libebml
May 6, 2026
Jan 29, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The EbmlUnicodeString::UpdateFromUTF8 function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted UTF-8 string, which triggers an invalid mem...Show more
The EbmlUnicodeString::UpdateFromUTF8 function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted UTF-8 string, which triggers an invalid memory access.Show less
1Matroska
1Libebml
May 6, 2026
Jan 29, 2016
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
Use-after-free vulnerability in the EbmlMaster::Read function in libEBML before 1.3.3 allows context-dependent attackers to have unspecified impact via a "deeply nested element with infinite size" followed by another ele...Show more
Use-after-free vulnerability in the EbmlMaster::Read function in libEBML before 1.3.3 allows context-dependent attackers to have unspecified impact via a "deeply nested element with infinite size" followed by another element of an upper level in an EBML document.Show less