Skip to content
Noroxi

webmproject records

25 published records for vendor webmproject.

Researcher profile

Entered KEV
2 · 8%
Weaponized
2 · 8%
Pre-auth RCE
1
With a fix record
88%
Median publish → KEV
3 days

All records

25 records
  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    google · chromeSep 12, 2023

  • Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to poten

    HighCVSS 8.8KEVWeaponizedEPSS 49%

    google · chromeSep 28, 2023

  • WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of s

    CriticalCVSS 9.8No exploitEPSS 5%

    google · chromeNov 5, 2010

  • A flaw was found in libwebp in versions before 1.0.1.

    CriticalCVSS 9.8No exploitEPSS 3%

    webmproject · libwebpMay 21, 2021

  • A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().

    CriticalCVSS 9.8No exploitEPSS 3%

    webmproject · libwebpMay 21, 2021

  • A flaw was found in libwebp in versions before 1.0.1.

    CriticalCVSS 9.8No exploitEPSS 2%

    webmproject · libwebpMay 21, 2021

  • A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

    CriticalCVSS 9.8No exploitEPSS 2%

    webmproject · libwebpMay 21, 2021

  • CVE-2018-6548
    39Monitor

    A use-after-free issue was discovered in libwebm through 2018-02-02.

    CriticalCVSS 9.8No exploitEPSS 1%

    webmproject · libwebmFeb 2, 2018

  • A flaw was found in libwebp in versions before 1.0.1.

    CriticalCVSS 9.1No exploitEPSS 2%

    webmproject · libwebpMay 21, 2021

  • A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().

    CriticalCVSS 9.1No exploitEPSS 2%

    webmproject · libwebpMay 21, 2021

  • A flaw was found in libwebp in versions before 1.0.1.

    CriticalCVSS 9.1No exploitEPSS 2%

    webmproject · libwebpMay 21, 2021

  • A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().

    CriticalCVSS 9.1No exploitEPSS 2%

    webmproject · libwebpMay 21, 2021

  • A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

    CriticalCVSS 9.1No exploitEPSS 2%

    webmproject · libwebpMay 21, 2021

  • A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

    CriticalCVSS 9.1No exploitEPSS 2%

    webmproject · libwebpMay 21, 2021

  • CVE-2018-6406
    36Monitor

    The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data o

    HighCVSS 8.8No exploitEPSS 2%

    webmproject · libwebmJan 30, 2018

  • A flaw was found in libwebp in versions before 1.0.1.

    HighCVSS 7.5No exploitEPSS 2%

    webmproject · libwebpMay 21, 2021

  • VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.

    HighCVSS 7.5No exploitEPSS 2%

    webmproject · libvpxSep 30, 2023

  • CVE-2019-9746
    30Monitor

    In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger

    HighCVSS 7.5No exploitEPSS 2%

    webmproject · libwebmMar 13, 2019

  • CVE-2016-9969
    30Monitor

    In libwebp 0.5.1, there is a double free bug in libwebpmux.

    HighCVSS 7.5No exploitEPSS 1%

    webmproject · libwebpMay 23, 2019

  • CVE-2023-1999
    30Monitor

    Use after free in libwebp

    HighCVSS 7.5Proof of conceptEPSS 1%

    webmproject · libwebpJun 20, 2023

  • In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack.

    MediumCVSS 6.5No exploitEPSS 1%

    webmproject · libwebmNov 12, 2018

  • CVE-2024-5197
    23Monitor

    Integer overflow in libvpx

    MediumCVSS 5.9No exploitEPSS 1%

    webmproject · libvpxJun 3, 2024

  • CVE-2023-6349
    22Monitor

    Heap overflow in libvpx

    MediumCVSS 5.7No exploitEPSS 0%

    webmproject · libvpxMay 27, 2024

  • CVE-2012-0823
    21Monitor

    VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "

    MediumCVSS 5.0No exploitEPSS 3%

    webmproject · libvpxFeb 23, 2012

  • CVE-2016-9085
    13Monitor

    Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.

    LowCVSS 3.3No exploitEPSS 0%

    webmproject · libwebpFeb 3, 2017