CVEs (15)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
9Bandisoft BentleyDebian+6 more12Active Iq Unified Manager ChromeDebian Linux+9 moreOct 24, 2025 Sep 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical...Show more |
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because...Show more |
4Debian NetappRedhat+1 more4Debian Linux Enterprise LinuxLibwebp+1 moreNov 21, 2024 May 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability. |
5Apple DebianNetapp+2 more6Debian Linux Enterprise LinuxIpados+3 moreNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability. |
5Apple DebianNetapp+2 more6Debian Linux Enterprise LinuxIpados+3 moreNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availabilit...Show more |
5Apple DebianNetapp+2 more6Debian Linux Enterprise LinuxIpados+3 moreNov 21, 2024 May 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as syst...Show more |
5Apple DebianNetapp+2 more6Debian Linux Enterprise LinuxIpados+3 moreNov 21, 2024 May 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data...Show more |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). |
In libwebp 0.5.1, there is a double free bug in libwebpmux. |
2Fedoraproject Webmproject2Fedora LibwebpMay 13, 2026 Feb 3, 2017 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors. |