cbcvebase.

Debian Libvpx vulnerabilities

26 known vulnerabilities affecting debian/libvpx.

Total CVEs
26
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH7MEDIUM11LOW4

Vulnerabilities

Page 1 of 2
CVE-2023-5217P1HIGHCVSS 8.8KEVPoCfixed in chromium 117.0.5938.132-1~deb12u1 (bookworm)2023
CVE-2023-5217 [HIGH] CVE-2023-5217: chromium - Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5... Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 117.0.5938.132-1~deb12u1) bullseye: resolved (fixed in 117.0.5938.132-1~deb11u1) forky: resolved
debian
CVE-2015-4485P3CRITICALCVSS 10.0fixed in libvpx 1.4.0-1 (bookworm)2015
CVE-2015-4485 [CRITICAL] CVE-2015-4485: libvpx - Heap-based buffer overflow in the resize_context_buffers function in libvpx in M... Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data. Scope: local bookworm: resolved (fixed in 1.4.0-1) bullseye: resolved (fixed in 1.4.0-1) forky: resolved (fixed in 1.4.0-1) sid: resolved (fixed i
debian
CVE-2016-1621P3CRITICALCVSS 9.8fixed in libvpx 1.6.1-1 (bookworm)2016
CVE-2016-1621 [CRITICAL] CVE-2016-1621: libvpx - libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and ... libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792. Scope: local bookworm: resolved (fixed in 1.6.1-1) bullseye: re
debian
CVE-2026-2447P3LOWCVSS 8.8fixed in firefox 147.0.4-1 (sid)2026
CVE-2026-2447 [HIGH] CVE-2026-2447: firefox - Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Fi... Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2. Scope: local sid: resolved (fixed in 147.0.4-1)
debian
CVE-2024-5197P3MEDIUMCVSS 5.9fixed in libvpx 1.12.0-1+deb12u3 (bookworm)2024
CVE-2024-5197 [MEDIUM] CVE-2024-5197: libvpx - There exists interger overflows in libvpx in versions prior to 1.14.1. Calling v... There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_ali
debian
CVE-2019-9232P3HIGHCVSS 7.5fixed in libvpx 1.8.1-2 (bookworm)2019
CVE-2019-9232 [HIGH] CVE-2019-9232: libvpx - In libvpx, there is a possible out of bounds read due to a missing bounds check.... In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483 Scope: local bookworm: resolved (fixed in 1.8.1-2) bullseye: resolved (fixed in 1.8.
debian
CVE-2015-4486P3CRITICALCVSS 10.0fixed in libvpx 1.4.0-1 (bookworm)2015
CVE-2015-4486 [CRITICAL] CVE-2015-4486: libvpx - The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Fir... The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed WebM video data. Scope: local bookworm: resolved (fixed in 1.4.0-1) bullseye: resolved (fixed in 1.4.0-1) forky: resolved (fixed in 1.4.0-1) sid: r
debian
CVE-2010-4203P3CRITICALCVSS 9.8fixed in libvpx 0.9.1-2 (bookworm)2010
CVE-2010-4203 [CRITICAL] CVE-2010-4203: libvpx - WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome befor... WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames. Scope: local bookworm: resolved (fixed in 0.9.1-2) bullseye: resolved (fixed in 0.9.1-2) forky: resolved (fixed in 0.9.1-2) sid: resolved (fixed
debian
CVE-2020-0034P3HIGHCVSS 7.5fixed in libvpx 1.7.0-3 (bookworm)2020
CVE-2020-0034 [HIGH] CVE-2020-0034: libvpx - In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due... In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770 Scope:
debian
CVE-2023-44488P3HIGHCVSS 7.5fixed in libvpx 1.12.0-1+deb12u2 (bookworm)2023
CVE-2023-44488 [HIGH] CVE-2023-44488: libvpx - VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to enc... VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding. Scope: local bookworm: resolved (fixed in 1.12.0-1+deb12u2) bullseye: resolved (fixed in 1.9.0-1+deb11u2) forky: resolved (fixed in 1.12.0-1.2) sid: resolved (fixed in 1.12.0-1.2) trixie: resolved (fixed in 1.12.0-1.2)
debian
CVE-2016-2464P3HIGHCVSS 7.8fixed in libvpx 1.6.1-1 (bookworm)2016
CVE-2016-2464 [HIGH] CVE-2016-2464: libvpx - libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2... libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, aka internal bug 23167726. Scope: local bookworm: resolved (fixed in 1.6.1-1) bullseye: resolved (fixed in 1.6.1-1) fork
debian
CVE-2015-4506P3LOWCVSS 6.8fixed in libvpx 1.4.0-4 (bookworm)2015
CVE-2015-4506 [MEDIUM] CVE-2015-4506: libvpx - Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in M... Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file. Scope: local bookworm: resolved (fixed in 1.4.0-4) bullseye: resolved (fixed in 1.4.0-4) forky: resolved (fixed in 1.4.0-4) sid: resolved (fixed in 1.4.0-
debian
CVE-2023-6349P3MEDIUMCVSS 5.7fixed in libvpx 1.12.0-1+deb12u2 (bookworm)2023
CVE-2023-6349 [MEDIUM] CVE-2023-6349: libvpx - A heap overflow vulnerability exists in libvpx - Encoding a frame that has large... A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1 or above Scope: local bookworm: resolved (fixed in 1.12.0-1+deb12u2) bullseye: resolved (fixed in 1.9.0-1+deb11u2) forky: resolved (fixed in 1.13.1-2
debian
CVE-2014-1578P3HIGHCVSS 7.5fixed in libvpx 1.3.0-3 (bookworm)2014
CVE-2014-1578 [HIGH] CVE-2014-1578: libvpx - The get_tile function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31... The get_tile function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly execute arbitrary code via WebM frames with invalid tile sizes that are improperly handled in buffering operations during video playback. Scope:
debian
CVE-2017-13194P3HIGHCVSS 7.5fixed in libvpx 1.7.0-2 (bookworm)2017
CVE-2017-13194 [HIGH] CVE-2017-13194: libvpx - A vulnerability in the Android media framework (libvpx) related to odd frame wid... A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201. Scope: local bookworm: resolved (fixed in 1.7.0-2) bullseye: resolved (fixed in 1.7.0-2) forky: resolved (fixed in 1.7.0-2) sid: resolved (fixed in 1.7.0-2) trixie: resolved (fixed in 1.7.0-2)
debian
CVE-2019-9371P3LOWCVSS 6.5fixed in libvpx 1.8.1-2 (bookworm)2019
CVE-2019-9371 [MEDIUM] CVE-2019-9371: libvpx - In libvpx, there is a possible resource exhaustion due to improper input validat... In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254 Scope: local bookworm: resolved (fixed in 1.8.1-2) bullseye: resolved (fixed in 1.8.1-2
debian
CVE-2019-9325P3MEDIUMCVSS 6.5fixed in libvpx 1.8.1-2 (bookworm)2019
CVE-2019-9325 [MEDIUM] CVE-2019-9325: libvpx - In libvpx, there is a possible out of bounds read due to a missing bounds check.... In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302 Scope: local bookworm: resolved (fixed in 1.8.1-2) bullseye: resolved (fixed in 1.8.1-
debian
CVE-2015-1258P4LOWCVSS 7.5fixed in libvpx 1.4.0-4 (bookworm)2015
CVE-2015-1258 [HIGH] CVE-2015-1258: libvpx - Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with ... Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data. Scope: local bookworm: resolved (fixed in 1.4.0-4)
debian
CVE-2019-9433P3MEDIUMCVSS 6.5fixed in libvpx 1.8.1-2 (bookworm)2019
CVE-2019-9433 [MEDIUM] CVE-2019-9433: libvpx - In libvpx, there is a possible information disclosure due to improper input vali... In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354 Scope: local bookworm: resolved (fixed in 1.8.1-2) bullseye: resolved (fixed in
debian
CVE-2025-5283P4MEDIUMCVSS 5.4fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5283 [MEDIUM] CVE-2025-5283: chromium - Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remot... Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1) bullseye: open forky: resolved (fixed in 137.0.7151.55-1) sid: resolved (fixed in 137.0.7151.55-1) trixie: r
debian
Debian Libvpx vulnerabilities | cvebase