Msrc Cm1 Libwebp 1.0.3-1 On Cbl Mariner 1.0 vulnerabilities
11 known vulnerabilities affecting msrc/cm1_libwebp_1.0.3-1_on_cbl_mariner_1.0.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH1
Vulnerabilities
Page 1 of 1
CVE-2020-36328CRITICALCVSS 9.82021-05-11
CVE-2020-36328 [CRITICAL] CWE-787 A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulne
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as syst
msrc
CVE-2020-36330CRITICALCVSS 9.12021-05-11
CVE-2020-36330 [CRITICAL] CWE-125 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.
FAQ: Is Azure Linux the only Microsoft pr
msrc
CVE-2018-25010CRITICALCVSS 9.12021-05-11
CVE-2018-25010 [CRITICAL] CWE-125 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the
msrc
CVE-2020-36331CRITICALCVSS 9.12021-05-11
CVE-2020-36331 [CRITICAL] CWE-125 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the serv
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
FAQ: Is Azure Linux the only Microsoft product
msrc
CVE-2018-25014CRITICALCVSS 9.82021-05-11
CVE-2018-25014 [CRITICAL] CWE-908 A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the mo
msrc
CVE-2018-25011CRITICALCVSS 9.82021-05-11
CVE-2018-25011 [CRITICAL] CWE-787 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most rec
msrc
CVE-2020-36329CRITICALCVSS 9.82021-05-11
CVE-2020-36329 [CRITICAL] CWE-416 A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integ
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
FAQ: Is Azure Linux the onl
msrc
CVE-2018-25013CRITICALCVSS 9.12021-05-11
CVE-2018-25013 [CRITICAL] CWE-125 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the mo
msrc
CVE-2018-25009CRITICALCVSS 9.12021-05-11
CVE-2018-25009 [CRITICAL] CWE-125 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most rec
msrc
CVE-2018-25012CRITICALCVSS 9.12021-05-11
CVE-2018-25012 [CRITICAL] CWE-125 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most rec
msrc
CVE-2020-36332HIGHCVSS 7.52021-05-11
CVE-2020-36332 [HIGH] CWE-400 A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-so
msrc