Libvorbis is a narrowly scoped audio-codec library widely embedded in media players, browsers, and streaming applications across multiple platforms, representing a supply-chain dependency rather than a directly exposed product. Its disclosed vulnerabilities cluster around audio-stream processing and parsing, reflecting the complexity inherent to codec implementations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libvorbis over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3106MEDIUM lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via inv | Jul 26, 2007 | 6.8 | 19 | NO | NO |
CVE-2007-4029MEDIUM libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalid mapping type, which triggers an out-of | Jul 26, 2007 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libvorbis.
Media articles that mention a CVE ID that affects a product developed by Libvorbis — matched by CVE ID, not by vendor name.