Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown

CVE-2017-14632

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.
Attacker Value
Unknown

CVE-2017-11331

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.
Attacker Value
Unknown

CVE-2017-11548

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file.
Attacker Value
Unknown

CVE-2017-11333

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.
0
Attacker Value
Unknown

CVE-2015-6749

Disclosure Date: September 21, 2015 (last updated October 05, 2023)
Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted AIFF file.
0
Attacker Value
Unknown

CVE-2015-3026

Disclosure Date: April 29, 2015 (last updated October 05, 2023)
Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."
0
Attacker Value
Unknown

CVE-2014-9639

Disclosure Date: January 23, 2015 (last updated October 05, 2023)
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.
0
Attacker Value
Unknown

CVE-2014-9638

Disclosure Date: January 23, 2015 (last updated October 05, 2023)
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.
0
Attacker Value
Unknown

CVE-2014-9640

Disclosure Date: January 23, 2015 (last updated October 05, 2023)
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.
0
Attacker Value
Unknown

CVE-2011-4612

Disclosure Date: November 20, 2012 (last updated October 05, 2023)
icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log) via a crafted URL.
0