Stb Vorbis is a single-file, header-only audio decoding library widely embedded in games, media players, and multimedia applications, where its modest disclosure volume belies its presence across a substantial installed base. The vulnerability pattern concentrates on memory-safety issues endemic to audio parsing—out-of-bounds reads and writes, NULL-pointer dereferences, divide-by-zero conditions, and buffer-boundary violations—reflecting the complexity of untrusted audio stream handling in a C implementation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stb Vorbis Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000050HIGH Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. that can result in memory corruption, denial of service, com | Feb 9, 2018 | 8.8 | 27 | NO | NO |
CVE-2019-13221HIGH A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a cr | Aug 15, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-13217HIGH A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted | Aug 15, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-13222HIGH An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive informatio | Aug 15, 2019 | 7.1 | 23 | NO | NO |
CVE-2019-13220HIGH Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive informatio | Aug 15, 2019 | 7.1 | 23 | NO | NO |
CVE-2019-13223MEDIUM A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. | Aug 15, 2019 | 5.5 | 19 | NO | NO |
CVE-2019-13219MEDIUM A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. | Aug 15, 2019 | 5.5 | 19 | NO | NO |
CVE-2019-13218MEDIUM Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. | Aug 15, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stb Vorbis Project.
Media articles that mention a CVE ID that affects a product developed by Stb Vorbis Project — matched by CVE ID, not by vendor name.