CVE-2023-47212
- EPSS 0.36%
- Veröffentlicht 01.05.2024 16:15:07
- Zuletzt bearbeitet 04.11.2025 18:15:42
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2019-13219
- EPSS 0.18%
- Veröffentlicht 15.08.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:24:28
A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.
CVE-2019-13220
- EPSS 0.14%
- Veröffentlicht 15.08.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:24:28
Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.
CVE-2019-13221
- EPSS 0.3%
- Veröffentlicht 15.08.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:24:28
A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.
CVE-2019-13222
- EPSS 0.14%
- Veröffentlicht 15.08.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:24:28
An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.
CVE-2019-13223
- EPSS 0.1%
- Veröffentlicht 15.08.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:24:28
A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.
CVE-2019-13217
- EPSS 0.3%
- Veröffentlicht 15.08.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:24:28
A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.
CVE-2019-13218
- EPSS 0.17%
- Veröffentlicht 15.08.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:24:28
Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.
CVE-2018-1000050
- EPSS 0.65%
- Veröffentlicht 09.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:39:31
Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. that can result in memory corruption, denial of service, comprised execution of host program. This attack appear to be exploitable...