xiph.org records
13 published records for vendor xiph.org.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 92.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-125 Out-of-bounds Read3
- CWE-189 Numeric Errors2
- CWE-129 Improper Validation of Array Index1
- CWE-20 Improper Input Validation1
- CWE-476 NULL Pointer Dereference1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2017-14632No exploit | Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.xiph.org · libvorbis · CWE-119 | Critical9.8 | — | 5.7% | Sep 21, 2017 |
39Monitor | CVE-2008-1423No exploit | Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause axiph.org · libvorbis · CWE-189 | Critical9.3 | — | 8.1% | May 16, 2008 |
36Monitor | CVE-2017-14160No exploit | The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds acxiph.org · libvorbis · CWE-119 | High8.8 | — | 4.6% | Sep 21, 2017 |
36Monitor | CVE-2018-10392No exploit | mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause xiph.org · libvorbis · CWE-125 | High8.8 | — | 3.3% | Apr 26, 2018 |
31Monitor | CVE-2018-10393No exploit | bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.xiph.org · libvorbis · CWE-125 | High7.5 | — | 2.4% | Apr 26, 2018 |
29Monitor | CVE-2008-1420No exploit | Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to exexiph.org · libvorbis · CWE-189 | Medium6.8 | — | 6.3% | May 16, 2008 |
27Monitor | CVE-2017-14633No exploit | In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lexiph.org · libvorbis · CWE-125 | Medium6.5 | — | 1.9% | Sep 21, 2017 |
26Monitor | CVE-2020-20412No exploit | lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a craftstepmania · stepmania · CWE-129 | Medium6.5 | — | 1.0% | Dec 26, 2020 |
23Monitor | CVE-2017-11333Proof of concept | The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) viaxiph.org · libvorbis · CWE-476 | Medium5.5 | — | 4.8% | Jul 31, 2017 |
18Monitor | CVE-2008-1419No exploit | Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denialxiph.org · libvorbis · CWE-20 | Medium4.3 | — | 4.3% | May 16, 2008 |
18Monitor | CVE-2008-2009No exploit | Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of sxiph.org · libvorbis | Medium4.3 | — | 3.5% | May 16, 2008 |
18Monitor | CVE-2007-4066No exploit | Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unxiph.org · libvorbis · CWE-119 | Medium4.3 | — | 1.8% | Sep 21, 2007 |
18Monitor | CVE-2007-4065No exploit | lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinixiph.org · libvorbis | Medium4.3 | — | 1.7% | Sep 21, 2007 |
- CVE-2017-1463241Plan
Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.
CriticalCVSS 9.8No exploitEPSS 6%xiph.org · libvorbisSep 21, 2017
- CVE-2008-142339Monitor
Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a
CriticalCVSS 9.3No exploitEPSS 8%xiph.org · libvorbisMay 16, 2008
- CVE-2017-1416036Monitor
The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds ac
HighCVSS 8.8No exploitEPSS 5%xiph.org · libvorbisSep 21, 2017
- CVE-2018-1039236Monitor
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause
HighCVSS 8.8No exploitEPSS 3%xiph.org · libvorbisApr 26, 2018
- CVE-2018-1039331Monitor
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
HighCVSS 7.5No exploitEPSS 2%xiph.org · libvorbisApr 26, 2018
- CVE-2008-142029Monitor
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to exe
MediumCVSS 6.8No exploitEPSS 6%xiph.org · libvorbisMay 16, 2008
- CVE-2017-1463327Monitor
In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may le
MediumCVSS 6.5No exploitEPSS 2%xiph.org · libvorbisSep 21, 2017
- CVE-2020-2041226Monitor
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a craft
MediumCVSS 6.5No exploitEPSS 1%stepmania · stepmaniaDec 26, 2020
- CVE-2017-1133323Monitor
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via
MediumCVSS 5.5Proof of conceptEPSS 5%xiph.org · libvorbisJul 31, 2017
- CVE-2008-141918Monitor
Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial
MediumCVSS 4.3No exploitEPSS 4%xiph.org · libvorbisMay 16, 2008
- CVE-2008-200918Monitor
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of s
MediumCVSS 4.3No exploitEPSS 4%xiph.org · libvorbisMay 16, 2008
- CVE-2007-406618Monitor
Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other un
MediumCVSS 4.3No exploitEPSS 2%xiph.org · libvorbisSep 21, 2007
- CVE-2007-406518Monitor
lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infini
MediumCVSS 4.3No exploitEPSS 2%xiph.org · libvorbisSep 21, 2007