VendorsWebM Projectlibvpxall versions
Vulnerabilities

WebM Project Libvpx

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2010-4203
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.
Published 2010-11-05 · Modified
10.0EPSS 0.046
CVE-2024-5197
Integer overflow in libvpx
Published 2024-06-03 · Analyzed
9.1EPSS 0.008
CVE-2023-5217
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-09-28 · Analyzed
8.8KEVEPSS 0.490
CVE-2023-44488
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
Published 2023-09-30 · Modified
7.5EPSS 0.019
CVE-2023-6349
Heap overflow in libvpx
Published 2024-05-27 · Analyzed
7.5EPSS 0.004
CVE-2012-0823
VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an out-of-bounds read, related to "the clamping of motion vectors in SPLITMV blocks".
Published 2012-02-23 · Modified
5.0EPSS 0.026