VYPR

Libebml

by Matroska

CVEs (3)

  • CVE-2015-8789CriJan 29, 2016
    risk 0.62cvss 9.6epss 0.00

    Use-after-free vulnerability in the EbmlMaster::Read function in libEBML before 1.3.3 allows context-dependent attackers to have unspecified impact via a "deeply nested element with infinite size" followed by another element of an upper level in an EBML document.

  • CVE-2015-8791MedJan 29, 2016
    risk 0.28cvss 4.3epss 0.00

    The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an invalid memory access.

  • CVE-2015-8790MedJan 29, 2016
    risk 0.28cvss 4.3epss 0.01

    The EbmlUnicodeString::UpdateFromUTF8 function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted UTF-8 string, which triggers an invalid memory access.