Libvorbis
Xiph.org · 13 CVEs
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds…
Dec 26, 2020
libvorbis: stack buffer overflow in bark_noise_hybridmp function
Apr 26, 2018
libvorbis: heap buffer overflow in mapping0_forward function
Apr 26, 2018
libvorbis: Out-of-bounds read in the bark_noise_hybridmp function
Sep 21, 2017
libvorbis: Out-of-bounds array read in the function mapping0_forward()
Sep 21, 2017
libvorbis: Invalid freeing of uninitialized memory in the function vorbis_analysis_headerout()
Sep 21, 2017
libvorbis: Memory exhaustion in vorbis_analysis_wrote function in lib/block.c
Jul 31, 2017
vorbis: insufficient validation of Huffman tree causing memory corruption in _make_decode_tree()
May 16, 2008
vorbis: integer oveflow caused by huge codebooks
May 16, 2008
vorbis: integer overflow in partvals computation
May 16, 2008
vorbis: zero-dim codebooks can cause crash, infinite loop or heap overflow
May 16, 2008
Multiple libvorbis flaws (CVE-2007-4066, CVE-2007-4029)
Sep 21, 2007
Multiple libvorbis flaws (CVE-2007-4066, CVE-2007-4029)
Sep 21, 2007
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-20412 | lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE:… | MEDIUM | 1.04% | Dec 26, 2020 |
| CVE-2018-10393 | libvorbis: stack buffer overflow in bark_noise_hybridmp function | HIGH | 2.38% | Apr 26, 2018 |
| CVE-2018-10392 | libvorbis: heap buffer overflow in mapping0_forward function | HIGH | 3.32% | Apr 26, 2018 |
| CVE-2017-14160 | libvorbis: Out-of-bounds read in the bark_noise_hybridmp function | HIGH | 4.58% | Sep 21, 2017 |
| CVE-2017-14633 | libvorbis: Out-of-bounds array read in the function mapping0_forward() | MEDIUM | 1.92% | Sep 21, 2017 |
| CVE-2017-14632 | libvorbis: Invalid freeing of uninitialized memory in the function vorbis_analysis_headerout() | CRITICAL | 5.71% | Sep 21, 2017 |
| CVE-2017-11333 | libvorbis: Memory exhaustion in vorbis_analysis_wrote function in lib/block.c | MEDIUM | 4.84% | Jul 31, 2017 |
| CVE-2008-2009 | vorbis: insufficient validation of Huffman tree causing memory corruption in _make_decode_tree() | MEDIUM | 3.51% | May 16, 2008 |
| CVE-2008-1423 | vorbis: integer oveflow caused by huge codebooks | HIGH | 8.13% | May 16, 2008 |
| CVE-2008-1420 | vorbis: integer overflow in partvals computation | MEDIUM | 6.32% | May 16, 2008 |
| CVE-2008-1419 | vorbis: zero-dim codebooks can cause crash, infinite loop or heap overflow | MEDIUM | 4.25% | May 16, 2008 |
| CVE-2007-4066 | Multiple libvorbis flaws (CVE-2007-4066, CVE-2007-4029) | MEDIUM | 1.84% | Sep 21, 2007 |
| CVE-2007-4065 | Multiple libvorbis flaws (CVE-2007-4066, CVE-2007-4029) | MEDIUM | 1.68% | Sep 21, 2007 |
Showing 1 to 13 of 13 CVEs