ZeroHour

Vulnerabilities

15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48174
+1 in the same advisory: …48175
In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.

In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.

NVD description · AI analysis pending
9.1
group max
<1%
  • aomedia libavif
CVE-2024-5171
Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow.

Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid. * Calling aom_img_wrap() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid. * Calling aom_img_alloc_with_border() with a large value of the d_w, d_h, align, size_align, or border parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid.

NVD description · AI analysis pending
10.01% PoC
  • aomedia libaom
CVE-2023-6879
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().

Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().

NVD description · AI analysis pending
9.81% PoC
  • aomedia aomedia
  • aomedia fedora
CVE-2023-39616
AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.

AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.

NVD description · AI analysis pending
7.5<1%
  • aomedia aomedia
CVE-2020-36133
AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h.

AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h.

NVD description · AI analysis pending
8.8
group max
2% PoC
  • aomedia aomedia
CVE-2020-36407
libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.

libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.

NVD description · AI analysis pending
8.81% PoC
  • aomedia libavif
CVE-2021-30475
aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.

aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.

NVD description · AI analysis pending
9.82%
  • aomedia aomedia
  • aomedia fedora
CVE-2021-30474
aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.

aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.

NVD description · AI analysis pending
9.82%
  • aomedia aomedia
CVE-2021-30473
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.

aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.

NVD description · AI analysis pending
9.82%
  • aomedia aomedia
  • aomedia fedora