Libass is a subtitle-rendering library embedded across media players and video processing tools, where its narrow product scope belies broad downstream distribution through open-source and commercial software. Its vulnerability profile reflects the parsing and buffer-management complexity inherent to font and subtitle format handling, with recurring weakness classes including resource-exhaustion conditions, buffer-boundary violations, integer overflows, and out-of-bounds read/write flaws. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libass Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24994HIGH Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service or remote code execution via a crafted f | Mar 23, 2021 | 8.8 | 28 | NO | NO |
CVE-2016-7970HIGH Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors. | Mar 3, 2017 | 7.5 | 27 | NO | NO |
CVE-2020-36430HIGH libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction. | Jul 20, 2021 | 7.8 | 26 | NO | NO |
CVE-2016-7969HIGH The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to | Mar 3, 2017 | 7.5 | 26 | NO | NO |
CVE-2020-26682HIGH In libass 0.14.0, the `ass_outline_construct`'s call to `outline_stroke` causes a signed integer overflow. | Oct 16, 2020 | 8.8 | 22 | NO | NO |
CVE-2016-7972HIGH The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vecto | Mar 3, 2017 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libass Project.
Media articles that mention a CVE ID that affects a product developed by Libass Project — matched by CVE ID, not by vendor name.