libaom
by Aomedia
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-5171 | Cri | 0.64 | 9.8 | 0.01 | Jun 5, 2024 | Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations… | ||
| CVE-2021-30475 | Cri | 0.64 | 9.8 | 0.02 | Jun 4, 2021 | aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow. | ||
| CVE-2021-30474 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2021 | aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free. | ||
| CVE-2021-30473 | Cri | 0.64 | 9.8 | 0.02 | May 6, 2021 | aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap. | ||
| CVE-2026-56211 | Hig | 0.46 | 7.1 | 0.00 | Jun 19, 2026 | A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal… | ||
| CVE-2026-56210 | Hig | 0.46 | 7.1 | 0.00 | Jun 19, 2026 | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an… |
- risk 0.64cvss 9.8epss 0.01
Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations…
- risk 0.64cvss 9.8epss 0.02
aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.
- risk 0.64cvss 9.8epss 0.02
aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.
- risk 0.64cvss 9.8epss 0.02
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
- risk 0.46cvss 7.1epss 0.00
A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal…
- risk 0.46cvss 7.1epss 0.00
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an…