Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
Unknown

CVE-2023-43361

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files.
Attacker Value
Unknown

CVE-2022-47021

Disclosure Date: January 20, 2023 (last updated October 08, 2023)
A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.
Attacker Value
Unknown

CVE-2020-23903

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.
Attacker Value
Unknown

CVE-2020-23904

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. NOTE: the vendor states "I cannot reproduce it" and it "is a demo program.
Attacker Value
Unknown

CVE-2020-20412

Disclosure Date: December 26, 2020 (last updated February 22, 2025)
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.
Attacker Value
Unknown

CVE-2018-18820

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.
0
Attacker Value
Unknown

CVE-2018-10392

Disclosure Date: April 26, 2018 (last updated November 26, 2024)
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.
Attacker Value
Unknown

CVE-2018-10393

Disclosure Date: April 26, 2018 (last updated November 26, 2024)
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
Attacker Value
Unknown

CVE-2017-14160

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file.
Attacker Value
Unknown

CVE-2017-14633

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().