Vulnerabilities
15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-48174 +1 in the same advisory: …48175 | In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size. In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size. NVD description · AI analysis pending | 9.1 group max | <1% |
| — | ||
| CVE-2024-5171 | Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid. * Calling aom_img_wrap() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid. * Calling aom_img_alloc_with_border() with a large value of the d_w, d_h, align, size_align, or border parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid. NVD description · AI analysis pending | 10.0 | 1% | PoC |
| — | |
| CVE-2023-6879 | Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2023-39616 | AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h. AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2020-36133 | AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h. AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h. NVD description · AI analysis pending | 8.8 group max | 2% | PoC |
| — | |
| CVE-2020-36407 | libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid. libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2021-30475 | aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow. aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2021-30474 | aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free. aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2021-30473 | aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap. aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap. NVD description · AI analysis pending | 9.8 | 2% |
| — |