Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2020-20412
Disclosure Date: December 26, 2020 (last updated February 22, 2025)
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.
0
Attacker Value
Unknown
CVE-2018-10392
Disclosure Date: April 26, 2018 (last updated November 26, 2024)
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.
0
Attacker Value
Unknown
CVE-2018-10393
Disclosure Date: April 26, 2018 (last updated November 26, 2024)
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
0
Attacker Value
Unknown
CVE-2017-14160
Disclosure Date: September 21, 2017 (last updated November 26, 2024)
The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file.
0
Attacker Value
Unknown
CVE-2017-14633
Disclosure Date: September 21, 2017 (last updated November 26, 2024)
In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().
0
Attacker Value
Unknown
CVE-2017-14632
Disclosure Date: September 21, 2017 (last updated November 26, 2024)
Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.
0
Attacker Value
Unknown
CVE-2017-11333
Disclosure Date: July 31, 2017 (last updated November 26, 2024)
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.
0
Attacker Value
Unknown
CVE-2008-1423
Disclosure Date: May 16, 2008 (last updated October 04, 2023)
Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.
0
Attacker Value
Unknown
CVE-2008-1419
Disclosure Date: May 16, 2008 (last updated October 04, 2023)
Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow.
0
Attacker Value
Unknown
CVE-2008-1420
Disclosure Date: May 16, 2008 (last updated October 04, 2023)
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.
0