Webmproject maintains a small but strategically important set of media-processing libraries—libwebp, libvpx, and libwebm—that are embedded across a vast range of browsers, messaging platforms, and multimedia applications, giving these components disproportionate reach despite their narrow product count. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and have a moderate tendency toward confirmed in-the-wild exploitation, reflecting the attack surface presented by parsing untrusted media files in high-privilege contexts. The recurring weakness classes—out-of-bounds reads and writes, integer overflows, use-after-free, and double-free conditions—are characteristic of memory-unsafe media codecs handling variable-length input, and they propagate downstream to every application that bundles these libraries. Defenders should treat Webmproject disclosures as broadly impactful and prioritize them across the browser and messaging infrastructure landscape, since remediation typically depends on downstream vendors rebuilding and shipping updates. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webmproject over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4863HIGH Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag | Sep 12, 2023 | 8.8 | 96 | YES | NO |
CVE-2023-5217HIGH Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra | Sep 28, 2023 | 8.8 | 87 | YES | NO |
CVE-2010-4203CRITICAL WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly e | Nov 6, 2010 | 9.8 | 32 | NO | NO |
CVE-2020-36329CRITICAL A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confi | May 21, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-25014CRITICAL A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). | May 21, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-25011CRITICAL A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). | May 21, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-36328CRITICAL A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest th | May 21, 2021 | 9.8 | 30 | NO | NO |
CVE-2024-5197CRITICAL There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflow | Jun 3, 2024 | 9.1 | 29 | NO | NO |
CVE-2018-25013CRITICAL A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). | May 21, 2021 | 9.1 | 29 | NO | NO |
CVE-2018-25012CRITICAL A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). | May 21, 2021 | 9.1 | 29 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webmproject.
Media articles that mention a CVE ID that affects a product developed by Webmproject — matched by CVE ID, not by vendor name.