Libaom
by Libaom
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-5171 | Cri | 0.64 | 9.8 | 0.01 | Jun 5, 2024 | Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations… | ||
| CVE-2023-6879 | Cri | 0.59 | 9.0 | 0.01 | Dec 27, 2023 | Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). | ||
| CVE-2026-56208 | imp | 0.49 | 7.6 | 0.00 | Jun 19, 2026 | libaom: libaom: heap buffer overflow in AV1 encoder first-pass stats buffer via LAP mode | ||
| CVE-2026-56210 | imp | 0.46 | 7.1 | 0.00 | Jun 19, 2026 | libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id | ||
| CVE-2026-56211 | imp | 0.46 | 7.1 | 0.00 | Jun 19, 2026 | libaom: libaom: remote code execution via SVC layer context handling with attacker-controlled frames | ||
| CVE-2026-56209 | imp | 0.46 | 7.1 | 0.01 | Jun 19, 2026 | libaom: libaom: arbitrary address write via SVC layer context OOB and cyclic refresh map pointer hijack |
- risk 0.64cvss 9.8epss 0.01
Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations…
- risk 0.59cvss 9.0epss 0.01
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
- risk 0.49cvss 7.6epss 0.00
libaom: libaom: heap buffer overflow in AV1 encoder first-pass stats buffer via LAP mode
- risk 0.46cvss 7.1epss 0.00
libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id
- risk 0.46cvss 7.1epss 0.00
libaom: libaom: remote code execution via SVC layer context handling with attacker-controlled frames
- risk 0.46cvss 7.1epss 0.01
libaom: libaom: arbitrary address write via SVC layer context OOB and cyclic refresh map pointer hijack