Webmproject
webmproject
25 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (25)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Webmproject2Debian Linux LibvpxJun 17, 2026 Jun 3, 2024 5.9 MEDIUM· v4 9.1 CRITICAL· v3 N/A· v2 There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes an...Show more |
A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Sep 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding. |
8Apple DebianFedoraproject+5 more11Chrome Debian LinuxEdge+8 moreJun 17, 2026 Sep 28, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever...Show more |
9Bandisoft BentleyDebian+6 more12Active Iq Unified Manager ChromeDebian Linux+9 moreJun 17, 2026 Sep 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical...Show more |
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because...Show more |
4Debian NetappRedhat+1 more4Debian Linux Enterprise LinuxLibwebp+1 moreJun 17, 2026 May 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability. |
5Apple DebianNetapp+2 more6Debian Linux Enterprise LinuxIpados+3 moreJun 17, 2026 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability. |
5Apple DebianNetapp+2 more6Debian Linux Enterprise LinuxIpados+3 moreJun 17, 2026 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availabilit...Show more |
5Apple DebianNetapp+2 more6Debian Linux Enterprise LinuxIpados+3 moreJun 17, 2026 May 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as syst...Show more |
5Apple DebianNetapp+2 more6Debian Linux Enterprise LinuxIpados+3 moreJun 17, 2026 May 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data...Show more |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). |
2Redhat Webmproject2Enterprise Linux LibwebpNov 21, 2024 May 21, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). |
In libwebp 0.5.1, there is a double free bug in libwebpmux. |
In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger an abort, which allows a DoS attack, a similar issue to CVE-2018-19212. |
In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack. |