Webmproject Libvpx vulnerabilities
27 known vulnerabilities affecting webmproject/libvpx.
Total CVEs
27
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH10MEDIUM13
Vulnerabilities
Page 1 of 2
CVE-2026-2447HIGHCVSS 8.8≥ 0, < 1.9.0-1+deb11u5≥ 0, < 1.12.0-1+deb12u5+2 more2026-02-16
CVE-2026-2447 [HIGH] CVE-2026-2447: Heap buffer overflow in libvpx
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.
osv
CVE-2025-5283MEDIUMCVSS 5.4≥ 0, < 1.9.0-1+deb11u4≥ 0, < 1.12.0-1+deb12u4+1 more2025-05-27
CVE-2025-5283 [MEDIUM] CVE-2025-5283: Use after free in libvpx in Google Chrome prior to 137
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
osv
CVE-2024-5197MEDIUMCVSS 5.9fixed in 1.14.12024-06-03
CVE-2024-5197 [MEDIUM] CWE-190 CVE-2024-5197: There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h
nvdosv
CVE-2023-6349MEDIUMCVSS 5.7fixed in 1.13.12024-05-27
CVE-2023-6349 [MEDIUM] CWE-122 CVE-2023-6349: A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than th
A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx.
We recommend upgrading to version 1.13.1 or above
nvdosv
CVE-2023-44488HIGHCVSS 7.5fixed in 1.13.12023-09-30
CVE-2023-44488 [HIGH] CWE-755 CVE-2023-44488: VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
nvdosv
CVE-2023-5217HIGHCVSS 8.8KEVfixed in 1.13.12023-09-28
CVE-2023-5217 [HIGH] CWE-787 CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvdosv
CVE-2020-0034HIGHCVSS 7.5≥ 0, < 1.7.0-32020-03-10
CVE-2020-0034 [HIGH] CVE-2020-0034: In vp8_decode_frame of decodeframe
In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770
osv
CVE-2019-9232HIGHCVSS 7.5≥ 0, < 1.8.1-22019-09-27
CVE-2019-9232 [HIGH] CVE-2019-9232: In libvpx, there is a possible out of bounds read due to a missing bounds check
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483
osv
CVE-2019-9325MEDIUMCVSS 6.5≥ 0, < 1.8.1-22019-09-27
CVE-2019-9325 [MEDIUM] CVE-2019-9325: In libvpx, there is a possible out of bounds read due to a missing bounds check
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302
osv
CVE-2019-9433MEDIUMCVSS 6.5≥ 0, < 1.8.1-22019-09-27
CVE-2019-9433 [MEDIUM] CVE-2019-9433: In libvpx, there is a possible information disclosure due to improper input validation
In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354
osv
CVE-2019-9371MEDIUMCVSS 6.5≥ 0, < 1.8.1-22019-09-27
CVE-2019-9371 [MEDIUM] CVE-2019-9371: In libvpx, there is a possible resource exhaustion due to improper input validation
In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254
osv
CVE-2019-2126HIGHCVSS 8.8≥ 0, < 1.7.0-3ubuntu0.18.04.12019-08-20
CVE-2019-2126 [HIGH] CVE-2019-2126: In ParseContentEncodingEntry of mkvparser
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127702368.
osv
CVE-2017-13194HIGHCVSS 7.5≥ 0, < 1.7.0-22018-01-12
CVE-2017-13194 [HIGH] CVE-2017-13194: A vulnerability in the Android media framework (libvpx) related to odd frame width
A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201.
osv
CVE-2017-0393MEDIUMCVSS 5.5≥ 0, < 1.6.1-12017-01-12
CVE-2017-0393 [MEDIUM] CVE-2017-0393: A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or re
A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Andr
osv
CVE-2016-6712MEDIUMCVSS 5.5≥ 0, < 1.6.1-12016-12-13
CVE-2016-6712 [MEDIUM] CVE-2016-6712: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593752.
osv
CVE-2016-6711MEDIUMCVSS 5.5≥ 0, < 1.6.1-12016-12-13
CVE-2016-6711 [MEDIUM] CVE-2016-6711: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593765.
osv
CVE-2016-3881MEDIUMCVSS 5.5≥ 0, < 1.6.1-12016-09-11
CVE-2016-3881 [MEDIUM] CVE-2016-3881: The decoder_peek_si_internal function in vp9/vp9_dx_iface
The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows remote attackers to cause a denial of service (buffer over-read, and device hang or reboot) via a crafted media file, aka internal bug 30013856.
osv
CVE-2016-2464HIGHCVSS 7.8≥ 0, < 1.6.1-12016-06-13
CVE-2016-2464 [HIGH] CVE-2016-2464: libvpx in libwebm in mediaserver in Android 4
libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, aka internal bug 23167726.
osv
CVE-2016-1621CRITICALCVSS 9.8≥ 0, < 1.6.1-12016-03-12
CVE-2016-1621 [CRITICAL] CVE-2016-1621: libvpx in mediaserver in Android 4
libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792.
osv
CVE-2015-4506MEDIUMCVSS 6.8≥ 0, < 1.4.0-42015-09-24
CVE-2015-4506 [MEDIUM] CVE-2015-4506: Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41
Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file.
osv
1 / 2Next →