cbcvebase.

Webmproject Libvpx vulnerabilities

27 known vulnerabilities affecting webmproject/libvpx.

Total CVEs
27
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH11MEDIUM11

Vulnerabilities

Page 2 of 2
CVE-2025-5283P4MEDIUMCVSS 5.4≥ 0, < 1.9.0-1+deb11u4≥ 0, < 1.12.0-1+deb12u4+1 more2025-05-27
CVE-2025-5283 [MEDIUM] CVE-2025-5283: Use after free in libvpx in Google Chrome prior to 137 Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
osv
CVE-2012-0823P4MEDIUMCVSS 5.0≤ 0.9.7v0.9.0+5 more2012-02-23
CVE-2012-0823 [MEDIUM] CWE-20 CVE-2012-0823: VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service ( VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an out-of-bounds read, related to "the clamping of motion vectors in SPLITMV blocks".
nvdosv
CVE-2017-0393P4MEDIUMCVSS 5.5≥ 0, < 1.6.1-12017-01-12
CVE-2017-0393 [MEDIUM] CVE-2017-0393: A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or re A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Andr
osv
CVE-2016-3881P4MEDIUMCVSS 5.5≥ 0, < 1.6.1-12016-09-11
CVE-2016-3881 [MEDIUM] CVE-2016-3881: The decoder_peek_si_internal function in vp9/vp9_dx_iface The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows remote attackers to cause a denial of service (buffer over-read, and device hang or reboot) via a crafted media file, aka internal bug 30013856.
osv
CVE-2016-6711P4MEDIUMCVSS 5.5≥ 0, < 1.6.1-12016-12-13
CVE-2016-6711 [MEDIUM] CVE-2016-6711: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4 A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593765.
osv
CVE-2016-6712P4MEDIUMCVSS 5.5≥ 0, < 1.6.1-12016-12-13
CVE-2016-6712 [MEDIUM] CVE-2016-6712: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4 A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593752.
osv
CVE-2010-4489P4MEDIUMCVSS 4.3≥ 0, < 0.9.5-12010-12-07
CVE-2010-4489 [MEDIUM] CVE-2010-4489: libvpx, as used in Google Chrome before 8 libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.
osv