VYPR
Vendor

Nothings

Products
4
CVEs
55
Across products
92
Status
Private

Products

4

Recent CVEs

55
View all 55 CVEs →
  • CVE-2023-47212CriMay 1, 2024
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2019-15058CriAug 14, 2019
    risk 0.59cvss 9.1epss 0.03

    stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Service.

  • CVE-2020-6623HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.

  • CVE-2020-6622HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.

  • CVE-2020-6621HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.

  • CVE-2020-6620HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.

  • CVE-2020-6619HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.

  • CVE-2020-6618HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.

  • CVE-2020-6617HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.

  • CVE-2019-19777HigDec 13, 2019
    risk 0.57cvss 8.8epss 0.01

    stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.

  • CVE-2018-16981HigSep 12, 2018
    risk 0.57cvss 8.8epss 0.02

    stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.

  • CVE-2018-1000050HigFeb 9, 2018
    risk 0.57cvss 8.8epss 0.02

    Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. that can result in memory corruption, denial of service, comprised execution of host program. This attack appear to be exploitable via Victim must open a…

  • CVE-2026-89266HigSep 12, 2026
    risk 0.53cvss 8.2epss 0.01

    stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes,…

  • CVE-2021-37789HigNov 2, 2022
    risk 0.53cvss 8.1epss 0.01

    stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

  • CVE-2019-13217HigAug 15, 2019
    risk 0.51cvss 7.8epss 0.02

    A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.

  • CVE-2022-25514HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.01

    stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.

  • CVE-2023-45666HigOct 21, 2023
    risk 0.48cvss 7.3epss 0.01

    stb_image is a single file MIT licensed library for processing images. It may look like `stbi__load_gif_main` doesn’t give guarantees about the content of output value `*delays` upon failure. Although it sets `*delays` to zero at the beginning, it doesn’t do it in case the…

  • CVE-2023-45664HigOct 21, 2023
    risk 0.48cvss 7.3epss 0.01

    stb_image is a single file MIT licensed library for processing images. A crafted image file can trigger `stbi__load_gif_main_outofmem` attempt to double-free the out variable. This happens in `stbi__load_gif_main` because when the `layers * stride` value is zero the behavior is…

  • CVE-2023-45681HigOct 21, 2023
    risk 0.47cvss 7.3epss 0.01

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory write past an allocated heap buffer in `start_decoder`. The root cause is a potential integer overflow in `sizeof(char*) * (f->comment_list_length)` which may make…

  • CVE-2023-45679HigOct 21, 2023
    risk 0.47cvss 7.3epss 0.01

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, but some of the pointers in `f->comment_list` are left initialized and later…