xiph.org kayıtları
xiph.org üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %92,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-125 Out-of-bounds Read3
- CWE-189 Numeric Errors2
- CWE-129 Improper Validation of Array Index1
- CWE-20 Improper Input Validation1
- CWE-476 NULL Pointer Dereference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2017-14632İstismar yok | Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.xiph.org · libvorbis · CWE-119 | Kritik9,8 | — | %5,7 | 21 Eyl 2017 |
39İzleyin | CVE-2008-1423İstismar yok | Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause axiph.org · libvorbis · CWE-189 | Kritik9,3 | — | %8,1 | 16 May 2008 |
36İzleyin | CVE-2017-14160İstismar yok | The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds acxiph.org · libvorbis · CWE-119 | Yüksek8,8 | — | %4,6 | 21 Eyl 2017 |
36İzleyin | CVE-2018-10392İstismar yok | mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause xiph.org · libvorbis · CWE-125 | Yüksek8,8 | — | %3,3 | 26 Nis 2018 |
31İzleyin | CVE-2018-10393İstismar yok | bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.xiph.org · libvorbis · CWE-125 | Yüksek7,5 | — | %2,4 | 26 Nis 2018 |
29İzleyin | CVE-2008-1420İstismar yok | Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to exexiph.org · libvorbis · CWE-189 | Orta6,8 | — | %6,3 | 16 May 2008 |
27İzleyin | CVE-2017-14633İstismar yok | In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lexiph.org · libvorbis · CWE-125 | Orta6,5 | — | %1,9 | 21 Eyl 2017 |
26İzleyin | CVE-2020-20412İstismar yok | lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a craftstepmania · stepmania · CWE-129 | Orta6,5 | — | %1,0 | 26 Ara 2020 |
23İzleyin | CVE-2017-11333Kavram kanıtı | The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) viaxiph.org · libvorbis · CWE-476 | Orta5,5 | — | %4,8 | 31 Tem 2017 |
18İzleyin | CVE-2008-1419İstismar yok | Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denialxiph.org · libvorbis · CWE-20 | Orta4,3 | — | %4,3 | 16 May 2008 |
18İzleyin | CVE-2008-2009İstismar yok | Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of sxiph.org · libvorbis | Orta4,3 | — | %3,5 | 16 May 2008 |
18İzleyin | CVE-2007-4066İstismar yok | Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unxiph.org · libvorbis · CWE-119 | Orta4,3 | — | %1,8 | 21 Eyl 2007 |
18İzleyin | CVE-2007-4065İstismar yok | lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinixiph.org · libvorbis | Orta4,3 | — | %1,7 | 21 Eyl 2007 |
- CVE-2017-1463241Planlayın
Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.
KritikCVSS 9,8İstismar yokEPSS %6xiph.org · libvorbis21 Eyl 2017
- CVE-2008-142339İzleyin
Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a
KritikCVSS 9,3İstismar yokEPSS %8xiph.org · libvorbis16 May 2008
- CVE-2017-1416036İzleyin
The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds ac
YüksekCVSS 8,8İstismar yokEPSS %5xiph.org · libvorbis21 Eyl 2017
- CVE-2018-1039236İzleyin
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause
YüksekCVSS 8,8İstismar yokEPSS %3xiph.org · libvorbis26 Nis 2018
- CVE-2018-1039331İzleyin
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
YüksekCVSS 7,5İstismar yokEPSS %2xiph.org · libvorbis26 Nis 2018
- CVE-2008-142029İzleyin
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to exe
OrtaCVSS 6,8İstismar yokEPSS %6xiph.org · libvorbis16 May 2008
- CVE-2017-1463327İzleyin
In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may le
OrtaCVSS 6,5İstismar yokEPSS %2xiph.org · libvorbis21 Eyl 2017
- CVE-2020-2041226İzleyin
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a craft
OrtaCVSS 6,5İstismar yokEPSS %1stepmania · stepmania26 Ara 2020
- CVE-2017-1133323İzleyin
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via
OrtaCVSS 5,5Kavram kanıtıEPSS %5xiph.org · libvorbis31 Tem 2017
- CVE-2008-141918İzleyin
Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial
OrtaCVSS 4,3İstismar yokEPSS %4xiph.org · libvorbis16 May 2008
- CVE-2008-200918İzleyin
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of s
OrtaCVSS 4,3İstismar yokEPSS %4xiph.org · libvorbis16 May 2008
- CVE-2007-406618İzleyin
Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other un
OrtaCVSS 4,3İstismar yokEPSS %2xiph.org · libvorbis21 Eyl 2007
- CVE-2007-406518İzleyin
lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infini
OrtaCVSS 4,3İstismar yokEPSS %2xiph.org · libvorbis21 Eyl 2007