Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webmproject

First CVE: Nov 6, 2010Active for: 16 yearsTotal CVEs: 25
66.4
VTI Score
TOP TARGET

Webmproject maintains a small but strategically important set of media-processing libraries—libwebp, libvpx, and libwebm—that are embedded across a vast range of browsers, messaging platforms, and multimedia applications, giving these components disproportionate reach despite their narrow product count. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and have a moderate tendency toward confirmed in-the-wild exploitation, reflecting the attack surface presented by parsing untrusted media files in high-privilege contexts. The recurring weakness classes—out-of-bounds reads and writes, integer overflows, use-after-free, and double-free conditions—are characteristic of memory-unsafe media codecs handling variable-length input, and they propagate downstream to every application that bundles these libraries. Defenders should treat Webmproject disclosures as broadly impactful and prioritize them across the browser and messaging infrastructure landscape, since remediation typically depends on downstream vendors rebuilding and shipping updates. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
8.0%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Webmproject over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 6, 2010
15 years ago
Most Recent CVE
Jun 3, 2024
781 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-4863HIGH
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag
Sep 12, 20238.896YESNO
CVE-2023-5217HIGH
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra
Sep 28, 20238.887YESNO
CVE-2010-4203CRITICAL
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly e
Nov 6, 20109.832NONO
CVE-2020-36329CRITICAL
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confi
May 21, 20219.831NONO
CVE-2018-25014CRITICAL
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
May 21, 20219.831NONO
CVE-2018-25011CRITICAL
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
May 21, 20219.831NONO
CVE-2020-36328CRITICAL
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest th
May 21, 20219.830NONO
CVE-2024-5197CRITICAL
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflow
Jun 3, 20249.129NONO
CVE-2018-25013CRITICAL
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
May 21, 20219.129NONO
CVE-2018-25012CRITICAL
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
May 21, 20219.129NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
36%
52%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.0%)
Network23 (92.0%)
Unknown1 (4.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High1 (4.0%)
Unknown1 (4.0%)
User Interaction
None19 (76.0%)
Unknown1 (4.0%)
Required5 (20.0%)
Privileges Required
Low1 (4.0%)
High0 (0.0%)
None23 (92.0%)
Unknown1 (4.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
2 CVEs
8.0% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webmproject.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webmproject — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webmproject's Products

View all 4 CNAs →

Top CWEs