webmproject kayıtları
webmproject üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %8
- Silahlaştırılmış
- 2 · %8
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %88
- Yayından KEV’e ortanca
- 3 gün
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read7
- CWE-787 Out-of-bounds Write4
- CWE-190 Integer Overflow or Wraparound3
- CWE-416 Use After Free3
- CWE-20 Improper Input Validation2
- CWE-122 Heap-based Buffer Overflow1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2023-4863Silahlaştırılmış | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | Yüksek8,8 | KEV | %100,0 | 12 Eyl 2023 |
80Hemen | CVE-2023-5217Silahlaştırılmış | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potengoogle · chrome · CWE-787 | Yüksek8,8 | KEV | %49,0 | 28 Eyl 2023 |
40Planlayın | CVE-2010-4203İstismar yok | WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of sgoogle · chrome · CWE-190 | Kritik9,8 | — | %4,6 | 5 Kas 2010 |
40Planlayın | CVE-2020-36328İstismar yok | A flaw was found in libwebp in versions before 1.0.1.webmproject · libwebp · CWE-787 | Kritik9,8 | — | %2,7 | 21 May 2021 |
40Planlayın | CVE-2018-25011İstismar yok | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().webmproject · libwebp · CWE-787 | Kritik9,8 | — | %2,5 | 21 May 2021 |
40Planlayın | CVE-2020-36329İstismar yok | A flaw was found in libwebp in versions before 1.0.1.webmproject · libwebp · CWE-416 | Kritik9,8 | — | %2,3 | 21 May 2021 |
40Planlayın | CVE-2018-25014İstismar yok | A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().webmproject · libwebp · CWE-908 | Kritik9,8 | — | %2,2 | 21 May 2021 |
39İzleyin | CVE-2018-6548İstismar yok | A use-after-free issue was discovered in libwebm through 2018-02-02.webmproject · libwebm · CWE-416 | Kritik9,8 | — | %1,4 | 2 Şub 2018 |
37İzleyin | CVE-2020-36331İstismar yok | A flaw was found in libwebp in versions before 1.0.1.webmproject · libwebp · CWE-125 | Kritik9,1 | — | %2,3 | 21 May 2021 |
37İzleyin | CVE-2018-25010İstismar yok | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().webmproject · libwebp · CWE-125 | Kritik9,1 | — | %2,2 | 21 May 2021 |
37İzleyin | CVE-2020-36330İstismar yok | A flaw was found in libwebp in versions before 1.0.1.webmproject · libwebp · CWE-125 | Kritik9,1 | — | %2,2 | 21 May 2021 |
37İzleyin | CVE-2018-25009İstismar yok | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().webmproject · libwebp · CWE-125 | Kritik9,1 | — | %2,1 | 21 May 2021 |
37İzleyin | CVE-2018-25012İstismar yok | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().webmproject · libwebp · CWE-125 | Kritik9,1 | — | %2,1 | 21 May 2021 |
37İzleyin | CVE-2018-25013İstismar yok | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().webmproject · libwebp · CWE-125 | Kritik9,1 | — | %2,1 | 21 May 2021 |
36İzleyin | CVE-2018-6406İstismar yok | The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data owebmproject · libwebm · CWE-125 | Yüksek8,8 | — | %2,0 | 30 Oca 2018 |
31İzleyin | CVE-2020-36332İstismar yok | A flaw was found in libwebp in versions before 1.0.1.webmproject · libwebp · CWE-20 | Yüksek7,5 | — | %2,0 | 21 May 2021 |
31İzleyin | CVE-2023-44488İstismar yok | VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.webmproject · libvpx · CWE-755 | Yüksek7,5 | — | %1,9 | 30 Eyl 2023 |
30İzleyin | CVE-2019-9746İstismar yok | In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will triggerwebmproject · libwebm · CWE-476 | Yüksek7,5 | — | %1,6 | 13 Mar 2019 |
30İzleyin | CVE-2016-9969İstismar yok | In libwebp 0.5.1, there is a double free bug in libwebpmux.webmproject · libwebp · CWE-415 | Yüksek7,5 | — | %1,4 | 23 May 2019 |
30İzleyin | CVE-2023-1999Kavram kanıtı | Use after free in libwebpwebmproject · libwebp · CWE-416 | Yüksek7,5 | — | %1,0 | 20 Haz 2023 |
26İzleyin | CVE-2018-19212İstismar yok | In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack.webmproject · libwebm · CWE-670 | Orta6,5 | — | %0,9 | 12 Kas 2018 |
23İzleyin | CVE-2024-5197İstismar yok | Integer overflow in libvpxwebmproject · libvpx · CWE-190 | Orta5,9 | — | %0,8 | 3 Haz 2024 |
22İzleyin | CVE-2023-6349İstismar yok | Heap overflow in libvpxwebmproject · libvpx · CWE-122 | Orta5,7 | — | %0,4 | 27 May 2024 |
21İzleyin | CVE-2012-0823İstismar yok | VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "webmproject · libvpx · CWE-20 | Orta5,0 | — | %2,6 | 23 Şub 2012 |
13İzleyin | CVE-2016-9085İstismar yok | Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.webmproject · libwebp · CWE-190 | Düşük3,3 | — | %0,4 | 3 Şub 2017 |
- CVE-2023-486395Hemen
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100google · chrome12 Eyl 2023
- CVE-2023-521780Hemen
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to poten
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %49google · chrome28 Eyl 2023
- CVE-2010-420340Planlayın
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of s
KritikCVSS 9,8İstismar yokEPSS %5google · chrome5 Kas 2010
- CVE-2020-3632840Planlayın
A flaw was found in libwebp in versions before 1.0.1.
KritikCVSS 9,8İstismar yokEPSS %3webmproject · libwebp21 May 2021
- CVE-2018-2501140Planlayın
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
KritikCVSS 9,8İstismar yokEPSS %3webmproject · libwebp21 May 2021
- CVE-2020-3632940Planlayın
A flaw was found in libwebp in versions before 1.0.1.
KritikCVSS 9,8İstismar yokEPSS %2webmproject · libwebp21 May 2021
- CVE-2018-2501440Planlayın
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
KritikCVSS 9,8İstismar yokEPSS %2webmproject · libwebp21 May 2021
- CVE-2018-654839İzleyin
A use-after-free issue was discovered in libwebm through 2018-02-02.
KritikCVSS 9,8İstismar yokEPSS %1webmproject · libwebm2 Şub 2018
- CVE-2020-3633137İzleyin
A flaw was found in libwebp in versions before 1.0.1.
KritikCVSS 9,1İstismar yokEPSS %2webmproject · libwebp21 May 2021
- CVE-2018-2501037İzleyin
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
KritikCVSS 9,1İstismar yokEPSS %2webmproject · libwebp21 May 2021
- CVE-2020-3633037İzleyin
A flaw was found in libwebp in versions before 1.0.1.
KritikCVSS 9,1İstismar yokEPSS %2webmproject · libwebp21 May 2021
- CVE-2018-2500937İzleyin
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
KritikCVSS 9,1İstismar yokEPSS %2webmproject · libwebp21 May 2021
- CVE-2018-2501237İzleyin
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
KritikCVSS 9,1İstismar yokEPSS %2webmproject · libwebp21 May 2021
- CVE-2018-2501337İzleyin
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
KritikCVSS 9,1İstismar yokEPSS %2webmproject · libwebp21 May 2021
- CVE-2018-640636İzleyin
The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data o
YüksekCVSS 8,8İstismar yokEPSS %2webmproject · libwebm30 Oca 2018
- CVE-2020-3633231İzleyin
A flaw was found in libwebp in versions before 1.0.1.
YüksekCVSS 7,5İstismar yokEPSS %2webmproject · libwebp21 May 2021
- CVE-2023-4448831İzleyin
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
YüksekCVSS 7,5İstismar yokEPSS %2webmproject · libvpx30 Eyl 2023
- CVE-2019-974630İzleyin
In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger
YüksekCVSS 7,5İstismar yokEPSS %2webmproject · libwebm13 Mar 2019
- CVE-2016-996930İzleyin
In libwebp 0.5.1, there is a double free bug in libwebpmux.
YüksekCVSS 7,5İstismar yokEPSS %1webmproject · libwebp23 May 2019
- CVE-2023-199930İzleyin
Use after free in libwebp
YüksekCVSS 7,5Kavram kanıtıEPSS %1webmproject · libwebp20 Haz 2023
- CVE-2018-1921226İzleyin
In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack.
OrtaCVSS 6,5İstismar yokEPSS %1webmproject · libwebm12 Kas 2018
- CVE-2024-519723İzleyin
Integer overflow in libvpx
OrtaCVSS 5,9İstismar yokEPSS %1webmproject · libvpx3 Haz 2024
- CVE-2023-634922İzleyin
Heap overflow in libvpx
OrtaCVSS 5,7İstismar yokEPSS %0webmproject · libvpx27 May 2024
- CVE-2012-082321İzleyin
VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "
OrtaCVSS 5,0İstismar yokEPSS %3webmproject · libvpx23 Şub 2012
- CVE-2016-908513İzleyin
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
DüşükCVSS 3,3İstismar yokEPSS %0webmproject · libwebp3 Şub 2017