Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xiph.org vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2008-1419
Xiph.org libvorbis 1.2.0 and previous versions does not properly handle a zero value for codebook.dim, which allows remote malicious users to cause a denial of service (crash or infinite loop) or trigger an integer overflow.
Xiph.org Libvorbis 1.1.0
Xiph.org Libvorbis 1.1.1
Xiph.org Libvorbis 1.0.0
Xiph.org Libvorbis 1.0.1
Xiph.org Libvorbis 1.12
Xiph.org Libvorbis 1.2.0
6.8
CVSSv2
CVE-2008-1420
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and previous versions allows remote malicious users to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.
Xiph.org Libvorbis 1.2.0
Xiph.org Libvorbis 1.0.1
Xiph.org Libvorbis 1.1.0
Xiph.org Libvorbis 1.1.1
Xiph.org Libvorbis 1.12
Xiph.org Libvorbis 1.0.0
9.3
CVSSv2
CVE-2008-1423
Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and previous versions allows remote malicious users to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, whi...
Xiph.org Libvorbis 1.0.0
Xiph.org Libvorbis 1.1.1
Xiph.org Libvorbis 1.1.2
Xiph.org Libvorbis 1.2.0
Xiph.org Libvorbis 1.0.1
Xiph.org Libvorbis 1.1.0
4.3
CVSSv2
CVE-2007-4065
lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis prior to 1.2.0 allows context-dependent malicious users to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217.
Xiph.org Libvorbis
4.3
CVSSv2
CVE-2007-4066
Multiple buffer overflows in Xiph.Org libvorbis prior to 1.2.0 allow context-dependent malicious users to cause a denial of service or have other unspecified impact via a crafted OGG file, aka trac Changesets 13162, 13168, 13169, 13170, 13172, 13211, and 13215, as demonstrated by...
Xiph.org Libvorbis
4.3
CVSSv2
CVE-2017-11333
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote malicious users to cause a denial of service (OOM) via a crafted wav file.
Xiph.org Libvorbis 1.3.5
1 EDB exploit
4.3
CVSSv2
CVE-2020-20412
lib/codebook.c in libvorbis prior to 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.
Xiph.org Libvorbis
Stepmania Stepmania 5.0.12
6.8
CVSSv2
CVE-2017-14160
The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote malicious users to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file.
Xiph.org Libvorbis 1.3.5
Debian Debian Linux 8.0
Debian Debian Linux 9.0
4.3
CVSSv2
CVE-2008-2009
Xiph.org libvorbis prior to 1.0 does not properly check for underpopulated Huffman trees, which allows remote malicious users to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.
Xiph.org Libvorbis 1.0
Canonical Ubuntu Linux 8.04
Canonical Ubuntu Linux 8.10
Canonical Ubuntu Linux 9.04
Canonical Ubuntu Linux 9.10
7.5
CVSSv2
CVE-2017-14632
Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.
Xiph.org Libvorbis 1.3.5
Debian Debian Linux 7.0
Debian Debian Linux 9.0
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 17.10
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »