VendorsWebM Projectlibwebpall versions
Vulnerabilities

WebM Project Webmproject libwebp

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2020-36328
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-05-21 · Modified
9.8EPSS 0.027
CVE-2018-25011
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
Published 2021-05-21 · Modified
9.8EPSS 0.025
CVE-2020-36329
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-05-21 · Modified
9.8EPSS 0.023
CVE-2018-25014
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
Published 2021-05-21 · Modified
9.8EPSS 0.022
CVE-2020-36331
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
Published 2021-05-21 · Modified
9.1EPSS 0.023
CVE-2018-25010
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
Published 2021-05-21 · Modified
9.1EPSS 0.022
CVE-2020-36330
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.
Published 2021-05-21 · Modified
9.1EPSS 0.022
CVE-2018-25009
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
Published 2021-05-21 · Modified
9.1EPSS 0.021
CVE-2018-25012
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
Published 2021-05-21 · Modified
9.1EPSS 0.021
CVE-2018-25013
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
Published 2021-05-21 · Modified
9.1EPSS 0.021
CVE-2023-4863
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Published 2023-09-12 · Analyzed
8.8KEVEPSS 1.000
CVE-2020-36332
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
Published 2021-05-21 · Modified
7.5EPSS 0.020
CVE-2016-9969
In libwebp 0.5.1, there is a double free bug in libwebpmux.
Published 2019-05-23 · Modified
7.5EPSS 0.014
CVE-2023-1999
Use after free in libwebp
Published 2023-06-20 · Modified
7.5EPSS 0.010
CVE-2016-9085
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
Published 2017-02-03 · Modified
3.3EPSS 0.004