cbcvebase.

Debian Libvpx vulnerabilities

26 known vulnerabilities affecting debian/libvpx.

Total CVEs
26
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH7MEDIUM11LOW4

Vulnerabilities

Page 2 of 2
CVE-2012-0823P4MEDIUMCVSS 5.0fixed in libvpx 1.0.0-1 (bookworm)2012
CVE-2012-0823 [MEDIUM] CVE-2012-0823: libvpx - VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a... VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an out-of-bounds read, related to "the clamping of motion vectors in SPLITMV blocks". Scope: local bookworm: resolved (fixed in 1.0.0-1) bullseye: resolv
debian
CVE-2017-0393P4MEDIUMCVSS 5.5fixed in libvpx 1.6.1-1 (bookworm)2017
CVE-2017-0393 [MEDIUM] CVE-2017-0393: libvpx - A denial of service vulnerability in libvpx in Mediaserver could enable a remote... A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808. Scope: local bookworm: resolved (fixed
debian
CVE-2016-3881P4MEDIUMCVSS 5.5fixed in libvpx 1.6.1-1 (bookworm)2016
CVE-2016-3881 [MEDIUM] CVE-2016-3881: libvpx - The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediase... The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows remote attackers to cause a denial of service (buffer over-read, and device hang or reboot) via a crafted media file, aka internal bug 30013856. Scope: local b
debian
CVE-2016-6711P4MEDIUMCVSS 5.5fixed in libvpx 1.6.1-1 (bookworm)2016
CVE-2016-6711 [MEDIUM] CVE-2016-6711: libvpx - A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x... A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593765. Scope: local
debian
CVE-2016-6712P4MEDIUMCVSS 5.5fixed in libvpx 1.6.1-1 (bookworm)2016
CVE-2016-6712 [MEDIUM] CVE-2016-6712: libvpx - A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x... A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593752. Scope: local
debian
CVE-2010-4489P4MEDIUMCVSS 4.3fixed in libvpx 0.9.5-1 (bookworm)2010
CVE-2010-4489 [MEDIUM] CVE-2010-4489: libvpx - libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products,... libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression. Scope: local bookworm: resolved (fixed in 0.9.5-1) bullseye: resolved (fixed in 0.9.5-1) forky: resolved (fixed in 0.9.5-1) sid: re
debian