Aomedia maintains a focused but widely integrated multimedia codec library whose vulnerabilities carry outsized impact due to deep embedding across media players, browsers, and content-delivery systems. Disclosures affecting the vendor skew strongly toward critical-severity outcomes, particularly through memory-safety weakness classes including out-of-bounds writes, integer overflows, buffer overflows, and NULL-pointer dereferences that are characteristic of native audio-video decoding logic. Defenders should treat updates to libavif and libaom as high-priority across all dependent products, since a codec flaw can compromise any application that processes untrusted media; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aomedia over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30474CRITICAL aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free. | Jun 2, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-30475CRITICAL aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow. | Jun 4, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-30473CRITICAL aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap. | May 6, 2021 | 9.8 | 30 | NO | NO |
CVE-2024-5171CRITICAL Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers:
* Calling aom_img_alloc() with a la | Jun 5, 2024 | 9.8 | 29 | NO | NO |
CVE-2020-36133HIGH AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h. | Dec 2, 2021 | 8.8 | 28 | NO | NO |
CVE-2020-36131HIGH AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c. | Dec 2, 2021 | 8.8 | 28 | NO | NO |
CVE-2020-36129HIGH AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c. | Dec 2, 2021 | 8.8 | 28 | NO | NO |
CVE-2025-48174CRITICAL In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size. | May 16, 2025 | 9.1 | 26 | NO | NO |
CVE-2023-6879CRITICAL Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). | Dec 27, 2023 | 9.8 | 26 | NO | NO |
CVE-2020-36407HIGH libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid. | Jul 1, 2021 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aomedia.
Media articles that mention a CVE ID that affects a product developed by Aomedia — matched by CVE ID, not by vendor name.