CVE-2023-4863
- EPSS 94.08%
- Veröffentlicht 12.09.2023 15:15:24
- Zuletzt bearbeitet 24.10.2025 14:07:28
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
CVE-2023-1999
- EPSS 0.62%
- Veröffentlicht 20.06.2023 12:15:09
- Zuletzt bearbeitet 13.02.2025 17:16:01
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in V...
CVE-2018-25009
- EPSS 0.45%
- Veröffentlicht 21.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 04:03:20
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
CVE-2018-25010
- EPSS 0.51%
- Veröffentlicht 21.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 04:03:20
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
CVE-2018-25011
- EPSS 0.38%
- Veröffentlicht 21.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 04:03:21
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
CVE-2018-25012
- EPSS 0.58%
- Veröffentlicht 21.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 04:03:21
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
CVE-2018-25013
- EPSS 0.14%
- Veröffentlicht 21.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 04:03:21
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
CVE-2018-25014
- EPSS 0.58%
- Veröffentlicht 21.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 04:03:21
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
CVE-2020-36328
- EPSS 0.53%
- Veröffentlicht 21.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:17
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity ...
CVE-2020-36329
- EPSS 0.5%
- Veröffentlicht 21.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:17
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.