Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Matroska

First CVE: Mar 10, 2008Active for: 18 yearsTotal CVEs: 16
14.2
VTI Score
Low

Matroska's vulnerability footprint concentrates in a small set of media-container parsing and validation tools—including mkclean, mkvalidator, and the libebml parsing library—that sit in the critical path of multimedia file processing across media players, editors, and transcoding pipelines. The recurring weakness classes, centered on improper input validation, NULL-pointer dereferences, integer overflows, and buffer-boundary failures, reflect the complexity and attack surface inherent to binary format parsing; these issues carry a tendency toward serious severity outcomes. Defenders should treat Matroska tooling as part of their media-handling risk surface, particularly in automated or user-facing transcoding workflows; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Matroska over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2008
18 years ago
Most Recent CVE
Jan 12, 2024
924 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-8789CRITICAL
Use-after-free vulnerability in the EbmlMaster::Read function in libEBML before 1.3.3 allows context-dependent attackers to have unspecified impact via a "deeply nested element wit
Jan 29, 20169.629NONO
CVE-2008-1161HIGH
Buffer overflow in the Matroska demuxer (demuxers/demux_matroska.c) in xine-lib before 1.1.10.1 allows remote attackers to cause a denial of service (crash) and possibly execute ar
Mar 10, 20089.325NONO
CVE-2021-3405MEDIUM
A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml.
Feb 23, 20216.523NONO
CVE-2017-12801MEDIUM
The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.
Nov 10, 20176.523NONO
CVE-2017-12800MEDIUM
The EBML_FindNextElement function in ebmlmain.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash)
Nov 10, 20176.523NONO
CVE-2017-12781MEDIUM
The EBML_BufferToID function in ebmlelement.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) v
Nov 10, 20176.521NONO
CVE-2017-12779MEDIUM
The Node_GetData function in corec/corec/node/node.c in mkvalidator 0.5.1 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via
Nov 10, 20176.521NONO
CVE-2017-12802MEDIUM
The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.
Nov 10, 20176.520NONO
CVE-2017-12783MEDIUM
The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.
Nov 10, 20176.520NONO
CVE-2017-12782MEDIUM
The ReadData function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.
Nov 10, 20176.520NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
88%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (93.8%)
Unknown1 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High0 (0.0%)
Unknown1 (6.3%)
User Interaction
None1 (6.3%)
Unknown1 (6.3%)
Required14 (87.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None15 (93.8%)
Unknown1 (6.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Matroska.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Matroska — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Matroska's Products

View all 2 CNAs →

Top CWEs