Matroska's vulnerability footprint concentrates in a small set of media-container parsing and validation tools—including mkclean, mkvalidator, and the libebml parsing library—that sit in the critical path of multimedia file processing across media players, editors, and transcoding pipelines. The recurring weakness classes, centered on improper input validation, NULL-pointer dereferences, integer overflows, and buffer-boundary failures, reflect the complexity and attack surface inherent to binary format parsing; these issues carry a tendency toward serious severity outcomes. Defenders should treat Matroska tooling as part of their media-handling risk surface, particularly in automated or user-facing transcoding workflows; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Matroska over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-8789CRITICAL Use-after-free vulnerability in the EbmlMaster::Read function in libEBML before 1.3.3 allows context-dependent attackers to have unspecified impact via a "deeply nested element wit | Jan 29, 2016 | 9.6 | 29 | NO | NO |
CVE-2008-1161HIGH Buffer overflow in the Matroska demuxer (demuxers/demux_matroska.c) in xine-lib before 1.1.10.1 allows remote attackers to cause a denial of service (crash) and possibly execute ar | Mar 10, 2008 | 9.3 | 25 | NO | NO |
CVE-2021-3405MEDIUM A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml. | Feb 23, 2021 | 6.5 | 23 | NO | NO |
CVE-2017-12801MEDIUM The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | Nov 10, 2017 | 6.5 | 23 | NO | NO |
CVE-2017-12800MEDIUM The EBML_FindNextElement function in ebmlmain.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) | Nov 10, 2017 | 6.5 | 23 | NO | NO |
CVE-2017-12781MEDIUM The EBML_BufferToID function in ebmlelement.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) v | Nov 10, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-12779MEDIUM The Node_GetData function in corec/corec/node/node.c in mkvalidator 0.5.1 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via | Nov 10, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-12802MEDIUM The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | Nov 10, 2017 | 6.5 | 20 | NO | NO |
CVE-2017-12783MEDIUM The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | Nov 10, 2017 | 6.5 | 20 | NO | NO |
CVE-2017-12782MEDIUM The ReadData function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | Nov 10, 2017 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Matroska.
Media articles that mention a CVE ID that affects a product developed by Matroska — matched by CVE ID, not by vendor name.