Debian Libvpx vulnerabilities
26 known vulnerabilities affecting debian/libvpx.
Total CVEs
26
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH7MEDIUM11LOW4
Vulnerabilities
Page 2 of 2
CVE-2012-0823P4MEDIUMCVSS 5.0fixed in libvpx 1.0.0-1 (bookworm)2012
CVE-2012-0823 [MEDIUM] CVE-2012-0823: libvpx - VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a...
VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an out-of-bounds read, related to "the clamping of motion vectors in SPLITMV blocks".
Scope: local
bookworm: resolved (fixed in 1.0.0-1)
bullseye: resolv
debian
CVE-2017-0393P4MEDIUMCVSS 5.5fixed in libvpx 1.6.1-1 (bookworm)2017
CVE-2017-0393 [MEDIUM] CVE-2017-0393: libvpx - A denial of service vulnerability in libvpx in Mediaserver could enable a remote...
A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808.
Scope: local
bookworm: resolved (fixed
debian
CVE-2016-3881P4MEDIUMCVSS 5.5fixed in libvpx 1.6.1-1 (bookworm)2016
CVE-2016-3881 [MEDIUM] CVE-2016-3881: libvpx - The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediase...
The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows remote attackers to cause a denial of service (buffer over-read, and device hang or reboot) via a crafted media file, aka internal bug 30013856.
Scope: local
b
debian
CVE-2016-6711P4MEDIUMCVSS 5.5fixed in libvpx 1.6.1-1 (bookworm)2016
CVE-2016-6711 [MEDIUM] CVE-2016-6711: libvpx - A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x...
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593765.
Scope: local
debian
CVE-2016-6712P4MEDIUMCVSS 5.5fixed in libvpx 1.6.1-1 (bookworm)2016
CVE-2016-6712 [MEDIUM] CVE-2016-6712: libvpx - A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x...
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593752.
Scope: local
debian
CVE-2010-4489P4MEDIUMCVSS 4.3fixed in libvpx 0.9.5-1 (bookworm)2010
CVE-2010-4489 [MEDIUM] CVE-2010-4489: libvpx - libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products,...
libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.
Scope: local
bookworm: resolved (fixed in 0.9.5-1)
bullseye: resolved (fixed in 0.9.5-1)
forky: resolved (fixed in 0.9.5-1)
sid: re
debian
← Previous2 / 2