Libvdpau is a video-decoding acceleration library that enables GPU-backed VDPAU (Video Decode and Presentation API for Unix) support across Linux systems and media applications. The library's narrow, focused scope presents a modest attack surface centered on path-traversal and input-validation weaknesses that can arise in file-access and configuration-parsing paths. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libvdpau Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-5199HIGH Directory traversal vulnerability in dlopen in libvdpau before 1.1.1 allows local users to gain privileges via the VDPAU_DRIVER environment variable. | Sep 8, 2015 | 7.2 | 18 | NO | NO |
CVE-2015-5198HIGH libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, related to the VDPAU_DRIVER_PATH environment vari | Sep 8, 2015 | 7.2 | 18 | NO | NO |
CVE-2015-5200MEDIUM The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors. | Sep 8, 2015 | 6.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libvdpau Project.
Media articles that mention a CVE ID that affects a product developed by Libvdpau Project — matched by CVE ID, not by vendor name.