Skip to content
Noroxi

xiph.org records

13 published records for vendor xiph.org.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
92.3%
Median publish → KEV
No record has entered KEV

All records

13 records
  • Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.

    CriticalCVSS 9.8No exploitEPSS 6%

    xiph.org · libvorbisSep 21, 2017

  • CVE-2008-1423
    39Monitor

    Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a

    CriticalCVSS 9.3No exploitEPSS 8%

    xiph.org · libvorbisMay 16, 2008

  • The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds ac

    HighCVSS 8.8No exploitEPSS 5%

    xiph.org · libvorbisSep 21, 2017

  • mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause

    HighCVSS 8.8No exploitEPSS 3%

    xiph.org · libvorbisApr 26, 2018

  • bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.

    HighCVSS 7.5No exploitEPSS 2%

    xiph.org · libvorbisApr 26, 2018

  • CVE-2008-1420
    29Monitor

    Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to exe

    MediumCVSS 6.8No exploitEPSS 6%

    xiph.org · libvorbisMay 16, 2008

  • In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may le

    MediumCVSS 6.5No exploitEPSS 2%

    xiph.org · libvorbisSep 21, 2017

  • lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a craft

    MediumCVSS 6.5No exploitEPSS 1%

    stepmania · stepmaniaDec 26, 2020

  • The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via

    MediumCVSS 5.5Proof of conceptEPSS 5%

    xiph.org · libvorbisJul 31, 2017

  • CVE-2008-1419
    18Monitor

    Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial

    MediumCVSS 4.3No exploitEPSS 4%

    xiph.org · libvorbisMay 16, 2008

  • CVE-2008-2009
    18Monitor

    Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of s

    MediumCVSS 4.3No exploitEPSS 4%

    xiph.org · libvorbisMay 16, 2008

  • CVE-2007-4066
    18Monitor

    Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other un

    MediumCVSS 4.3No exploitEPSS 2%

    xiph.org · libvorbisSep 21, 2007

  • CVE-2007-4065
    18Monitor

    lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infini

    MediumCVSS 4.3No exploitEPSS 2%

    xiph.org · libvorbisSep 21, 2007