← Back

Xiph

xiph

17 CVEs • 8 products

Products (8)

Click to collapse
Toggle
Vorbis Tools
vorbis-tools
Speex
speex
Icecast
icecast
Theora
theora
Libfishsound
libfishsound
Libao
libao
Opusfile
opusfile

CVEs (17)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Redhat
Xiph
2Enterprise Linux
Theora
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit t...Show more
A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.Show less
1Xiph
1Theora
Jun 17, 2026
Dec 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an applicat...Show more
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.Show less
1Xiph
1Vorbis Tools
Jun 17, 2026
Oct 2, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files.
2Fedoraproject
Xiph
2Fedora
Opusfile
Jun 17, 2026
Jan 20, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.
1Xiph
1Speex
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. NOTE: the vendor states "I cannot reproduce it" and it "is a demo program.
2Fedoraproject
Xiph
2Fedora
Speex
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.
2Debian
Xiph
2Debian Linux
Icecast
Nov 21, 2024
Nov 5, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted...Show more
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.Show less
1Xiph
1Libao
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file.
1Xiph
1Vorbis Tools
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.
1Xiph
1Vorbis Tools
May 6, 2026
Sep 21, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted AIFF file.
3Debian
OpensuseXiph
3Debian Linux
IcecastOpensuse
May 6, 2026
Apr 29, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as de...Show more
Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."Show less
2Opensuse
Xiph
2Opensuse
Vorbis Tools
May 6, 2026
Jan 23, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.
3Fedoraproject
OpensuseXiph
3Fedora
OpensuseVorbis Tools
May 6, 2026
Jan 23, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.
3Fedoraproject
OpensuseXiph
3Fedora
OpensuseVorbis Tools
May 6, 2026
Jan 23, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.
1Xiph
1Icecast
Apr 29, 2026
Nov 20, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log) via a crafted URL.
2Xine
Xiph
3Libfishsound
SpeexXine Lib
Apr 23, 2026
Apr 8, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products,...Show more
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.Show less
1Xiph
1Icecast Ezstream
Apr 23, 2026
Mar 8, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlParse function, which causes a stack-base...Show more
Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlParse function, which causes a stack-based overflow and the (2) ReplaceString function, which causes a heap-based overflow. NOTE: some of these details are obtained from third party information.Show less