Xiph develops audio and video codec libraries and streaming software that see wide deployment in media servers and playback tools, despite a narrowly focused product portfolio. Vulnerabilities affecting the vendor concentrate in memory-handling and input-validation weaknesses—including buffer-boundary violations, out-of-bounds writes, and divide-by-zero conditions—that recur across products such as Vorbis Tools, Icecast, Speex, and Theora, and frequently acquire public exploit code. A meaningful share of these disclosures reach serious severity; defenders should treat codec and streaming-infrastructure updates from this vendor as having elevated priority given the parser complexity of media formats and the potential for remote code execution through malformed files. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xiph over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18820HIGH A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for tha | Nov 5, 2018 | 8.1 | 53 | NO | NO |
CVE-2017-11548MEDIUM The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file. | Jul 31, 2017 | 5.5 | 30 | NO | YES |
CVE-2017-11331MEDIUM The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file. | Jul 31, 2017 | 5.5 | 28 | NO | YES |
CVE-2024-56431CRITICAL oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence | Dec 25, 2024 | 9.8 | 27 | NO | NO |
CVE-2007-1344HIGH Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlP | Mar 8, 2007 | 9.3 | 26 | NO | NO |
CVE-2026-5673HIGH A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() fu | Apr 6, 2026 | 7.1 | 25 | NO | NO |
CVE-2022-47021HIGH A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or ot | Jan 20, 2023 | 7.8 | 25 | NO | NO |
CVE-2008-1686HIGH Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib | Apr 8, 2008 | 9.3 | 25 | NO | NO |
CVE-2023-43361HIGH Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg file | Oct 2, 2023 | 7.8 | 22 | NO | NO |
CVE-2020-23903MEDIUM A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. | Nov 10, 2021 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xiph.
Media articles that mention a CVE ID that affects a product developed by Xiph — matched by CVE ID, not by vendor name.