Xiph.Org maintains widely deployed audio and multimedia codecs, most prominently libvorbis, that are embedded across media players, streaming applications, and browser implementations. The vendor's vulnerability profile centers on memory-safety and input-validation weaknesses inherent to codec parsers, including buffer-bounds violations, out-of-bounds reads, and improper array indexing, which carry a meaningful tendency toward serious severity and public exploit availability. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xiph.Org over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14160HIGH The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly | Sep 21, 2017 | 8.8 | 31 | NO | NO |
CVE-2018-10392HIGH mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer o | Apr 26, 2018 | 8.8 | 29 | NO | NO |
CVE-2008-1423HIGH Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute ar | May 16, 2008 | 9.3 | 28 | NO | NO |
CVE-2017-14632CRITICAL Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue | Sep 21, 2017 | 9.8 | 26 | NO | NO |
CVE-2018-10393HIGH bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read. | Apr 26, 2018 | 7.5 | 25 | NO | NO |
CVE-2017-11333MEDIUM The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file. | Jul 31, 2017 | 5.5 | 25 | NO | YES |
CVE-2008-1420MEDIUM Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG fi | May 16, 2008 | 6.8 | 24 | NO | NO |
CVE-2020-20412MEDIUM lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE- | Dec 26, 2020 | 6.5 | 22 | NO | NO |
CVE-2017-14633MEDIUM In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted au | Sep 21, 2017 | 6.5 | 22 | NO | NO |
CVE-2008-2009MEDIUM Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file th | May 16, 2008 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xiph.Org.
Media articles that mention a CVE ID that affects a product developed by Xiph.Org — matched by CVE ID, not by vendor name.