Xiph Speex vulnerabilities
3 known vulnerabilities affecting xiph/speex.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-23904MEDIUMCVSS 5.5v1.22021-11-10
CVE-2020-23904 [MEDIUM] CWE-787 CVE-2020-23904: A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (D
A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. NOTE: the vendor states "I cannot reproduce it" and it "is a demo program.
nvd
CVE-2020-23903MEDIUMCVSS 5.5v1.22021-11-10
CVE-2020-23903 [MEDIUM] CWE-369 CVE-2020-23903: A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attacker
A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.
nvdosv
CVE-2008-1686CRITICALCVSS 9.3≤ 1.1.12v1.0.2+15 more2008-04-08
CVE-2008-1686 [CRITICAL] CWE-189 CVE-2008-1686: Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, in
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereferenc
nvdosv