webmproject records
25 published records for vendor webmproject.
Researcher profile
- Entered KEV
- 2 · 8%
- Weaponized
- 2 · 8%
- Pre-auth RCE
- 1
- With a fix record
- 88%
- Median publish → KEV
- 3 days
Recurring classes
- CWE-125 Out-of-bounds Read7
- CWE-787 Out-of-bounds Write4
- CWE-190 Integer Overflow or Wraparound3
- CWE-416 Use After Free3
- CWE-20 Improper Input Validation2
- CWE-122 Heap-based Buffer Overflow1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
25 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2023-4863Weaponized | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | High8.8 | KEV | 100.0% | Sep 12, 2023 |
80Now | CVE-2023-5217Weaponized | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potengoogle · chrome · CWE-787 | High8.8 | KEV | 49.0% | Sep 28, 2023 |
40Plan | CVE-2010-4203No exploit | WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of sgoogle · chrome · CWE-190 | Critical9.8 | — | 4.6% | Nov 5, 2010 |
40Plan | CVE-2020-36328No exploit | A flaw was found in libwebp in versions before 1.0.1.webmproject · libwebp · CWE-787 | Critical9.8 | — | 2.7% | May 21, 2021 |
40Plan | CVE-2018-25011No exploit | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().webmproject · libwebp · CWE-787 | Critical9.8 | — | 2.5% | May 21, 2021 |
40Plan | CVE-2020-36329No exploit | A flaw was found in libwebp in versions before 1.0.1.webmproject · libwebp · CWE-416 | Critical9.8 | — | 2.3% | May 21, 2021 |
40Plan | CVE-2018-25014No exploit | A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().webmproject · libwebp · CWE-908 | Critical9.8 | — | 2.2% | May 21, 2021 |
39Monitor | CVE-2018-6548No exploit | A use-after-free issue was discovered in libwebm through 2018-02-02.webmproject · libwebm · CWE-416 | Critical9.8 | — | 1.4% | Feb 2, 2018 |
37Monitor | CVE-2020-36331No exploit | A flaw was found in libwebp in versions before 1.0.1.webmproject · libwebp · CWE-125 | Critical9.1 | — | 2.3% | May 21, 2021 |
37Monitor | CVE-2018-25010No exploit | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().webmproject · libwebp · CWE-125 | Critical9.1 | — | 2.2% | May 21, 2021 |
37Monitor | CVE-2020-36330No exploit | A flaw was found in libwebp in versions before 1.0.1.webmproject · libwebp · CWE-125 | Critical9.1 | — | 2.2% | May 21, 2021 |
37Monitor | CVE-2018-25009No exploit | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().webmproject · libwebp · CWE-125 | Critical9.1 | — | 2.1% | May 21, 2021 |
37Monitor | CVE-2018-25012No exploit | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().webmproject · libwebp · CWE-125 | Critical9.1 | — | 2.1% | May 21, 2021 |
37Monitor | CVE-2018-25013No exploit | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().webmproject · libwebp · CWE-125 | Critical9.1 | — | 2.1% | May 21, 2021 |
36Monitor | CVE-2018-6406No exploit | The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data owebmproject · libwebm · CWE-125 | High8.8 | — | 2.0% | Jan 30, 2018 |
31Monitor | CVE-2020-36332No exploit | A flaw was found in libwebp in versions before 1.0.1.webmproject · libwebp · CWE-20 | High7.5 | — | 2.0% | May 21, 2021 |
31Monitor | CVE-2023-44488No exploit | VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.webmproject · libvpx · CWE-755 | High7.5 | — | 1.9% | Sep 30, 2023 |
30Monitor | CVE-2019-9746No exploit | In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will triggerwebmproject · libwebm · CWE-476 | High7.5 | — | 1.6% | Mar 13, 2019 |
30Monitor | CVE-2016-9969No exploit | In libwebp 0.5.1, there is a double free bug in libwebpmux.webmproject · libwebp · CWE-415 | High7.5 | — | 1.4% | May 23, 2019 |
30Monitor | CVE-2023-1999Proof of concept | Use after free in libwebpwebmproject · libwebp · CWE-416 | High7.5 | — | 1.0% | Jun 20, 2023 |
26Monitor | CVE-2018-19212No exploit | In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack.webmproject · libwebm · CWE-670 | Medium6.5 | — | 0.9% | Nov 12, 2018 |
23Monitor | CVE-2024-5197No exploit | Integer overflow in libvpxwebmproject · libvpx · CWE-190 | Medium5.9 | — | 0.8% | Jun 3, 2024 |
22Monitor | CVE-2023-6349No exploit | Heap overflow in libvpxwebmproject · libvpx · CWE-122 | Medium5.7 | — | 0.4% | May 27, 2024 |
21Monitor | CVE-2012-0823No exploit | VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "webmproject · libvpx · CWE-20 | Medium5.0 | — | 2.6% | Feb 23, 2012 |
13Monitor | CVE-2016-9085No exploit | Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.webmproject · libwebp · CWE-190 | Low3.3 | — | 0.4% | Feb 3, 2017 |
- CVE-2023-486395Now
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
HighCVSS 8.8KEVWeaponizedEPSS 100%google · chromeSep 12, 2023
- CVE-2023-521780Now
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to poten
HighCVSS 8.8KEVWeaponizedEPSS 49%google · chromeSep 28, 2023
- CVE-2010-420340Plan
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of s
CriticalCVSS 9.8No exploitEPSS 5%google · chromeNov 5, 2010
- CVE-2020-3632840Plan
A flaw was found in libwebp in versions before 1.0.1.
CriticalCVSS 9.8No exploitEPSS 3%webmproject · libwebpMay 21, 2021
- CVE-2018-2501140Plan
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
CriticalCVSS 9.8No exploitEPSS 3%webmproject · libwebpMay 21, 2021
- CVE-2020-3632940Plan
A flaw was found in libwebp in versions before 1.0.1.
CriticalCVSS 9.8No exploitEPSS 2%webmproject · libwebpMay 21, 2021
- CVE-2018-2501440Plan
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
CriticalCVSS 9.8No exploitEPSS 2%webmproject · libwebpMay 21, 2021
- CVE-2018-654839Monitor
A use-after-free issue was discovered in libwebm through 2018-02-02.
CriticalCVSS 9.8No exploitEPSS 1%webmproject · libwebmFeb 2, 2018
- CVE-2020-3633137Monitor
A flaw was found in libwebp in versions before 1.0.1.
CriticalCVSS 9.1No exploitEPSS 2%webmproject · libwebpMay 21, 2021
- CVE-2018-2501037Monitor
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
CriticalCVSS 9.1No exploitEPSS 2%webmproject · libwebpMay 21, 2021
- CVE-2020-3633037Monitor
A flaw was found in libwebp in versions before 1.0.1.
CriticalCVSS 9.1No exploitEPSS 2%webmproject · libwebpMay 21, 2021
- CVE-2018-2500937Monitor
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
CriticalCVSS 9.1No exploitEPSS 2%webmproject · libwebpMay 21, 2021
- CVE-2018-2501237Monitor
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
CriticalCVSS 9.1No exploitEPSS 2%webmproject · libwebpMay 21, 2021
- CVE-2018-2501337Monitor
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
CriticalCVSS 9.1No exploitEPSS 2%webmproject · libwebpMay 21, 2021
- CVE-2018-640636Monitor
The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data o
HighCVSS 8.8No exploitEPSS 2%webmproject · libwebmJan 30, 2018
- CVE-2020-3633231Monitor
A flaw was found in libwebp in versions before 1.0.1.
HighCVSS 7.5No exploitEPSS 2%webmproject · libwebpMay 21, 2021
- CVE-2023-4448831Monitor
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
HighCVSS 7.5No exploitEPSS 2%webmproject · libvpxSep 30, 2023
- CVE-2019-974630Monitor
In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger
HighCVSS 7.5No exploitEPSS 2%webmproject · libwebmMar 13, 2019
- CVE-2016-996930Monitor
In libwebp 0.5.1, there is a double free bug in libwebpmux.
HighCVSS 7.5No exploitEPSS 1%webmproject · libwebpMay 23, 2019
- CVE-2023-199930Monitor
Use after free in libwebp
HighCVSS 7.5Proof of conceptEPSS 1%webmproject · libwebpJun 20, 2023
- CVE-2018-1921226Monitor
In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack.
MediumCVSS 6.5No exploitEPSS 1%webmproject · libwebmNov 12, 2018
- CVE-2024-519723Monitor
Integer overflow in libvpx
MediumCVSS 5.9No exploitEPSS 1%webmproject · libvpxJun 3, 2024
- CVE-2023-634922Monitor
Heap overflow in libvpx
MediumCVSS 5.7No exploitEPSS 0%webmproject · libvpxMay 27, 2024
- CVE-2012-082321Monitor
VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "
MediumCVSS 5.0No exploitEPSS 3%webmproject · libvpxFeb 23, 2012
- CVE-2016-908513Monitor
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
LowCVSS 3.3No exploitEPSS 0%webmproject · libwebpFeb 3, 2017