VendorsNothingsstb_vorbis.call versions
Vulnerabilities

Nothings stb_vorbis.c

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2023-47212
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-05-01 · Modified
9.8EPSS 0.014
CVE-2026-5317
Nothings stb stb_vorbis.c start_decoder out-of-bounds write
Published 2026-04-02 · Analyzed
8.8EPSS 0.006
CVE-2023-45675
0 byte write heap buffer overflow in start_decoder in stb_vorbis
Published 2023-10-20 · Modified
7.8EPSS 0.008
CVE-2023-45678
Off-by-one heap buffer write in start_decoder in stb_vorbis
Published 2023-10-20 · Modified
7.8EPSS 0.007
CVE-2023-45677
Heap buffer out of bounds write in start_decoder in stb_vorbis
Published 2023-10-20 · Modified
7.8EPSS 0.005
CVE-2023-45681
Out of bounds heap buffer write in stb_vorbis
Published 2023-10-20 · Modified
7.8EPSS 0.005
CVE-2023-45676
Multi-byte write heap buffer overflow in start_decoder in stb_vorbis
Published 2023-10-20 · Modified
7.8EPSS 0.005
CVE-2023-45679
Attempt to free an uninitialized memory pointer in vorbis_deinit in stb_vorbis
Published 2023-10-20 · Modified
7.8EPSS 0.005
CVE-2023-45682
Wild address read in vorbis_decode_packet_rest in stb_vorbis
Published 2023-10-20 · Modified
7.1EPSS 0.006
CVE-2026-5316
Nothings stb stb_vorbis.c setup_free allocation of resources
Published 2026-04-02 · Analyzed
6.5EPSS 0.007
CVE-2023-45680
Null pointer dereference in vorbis_deinit in stb_vorbis
Published 2023-10-20 · Modified
5.5EPSS 0.005