Libvorbis
Vendor:
First CVE: Sep 21, 2007 · Active for 18 years
13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libvorbis over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2007
18 years ago
Most Recent CVE
Dec 26, 2020
2,036 days ago
CVE Severity & Scoring
Libvorbis13 CVEs
62%
31%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.7%)
Network6 (46.2%)
Unknown6 (46.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (53.8%)
High0 (0.0%)
Unknown6 (46.2%)
User Interaction
None2 (15.4%)
Unknown6 (46.2%)
Required5 (38.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (53.8%)
Unknown6 (46.2%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14160HIGH The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly | Sep 21, 2017 | 8.8 | 31 | NO | NO |
CVE-2018-10392HIGH mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer o | Apr 26, 2018 | 8.8 | 29 | NO | NO |
CVE-2008-1423HIGH Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute ar | May 16, 2008 | 9.3 | 28 | NO | NO |
CVE-2017-14632CRITICAL Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue | Sep 21, 2017 | 9.8 | 26 | NO | NO |
CVE-2018-10393HIGH bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read. | Apr 26, 2018 | 7.5 | 25 | NO | NO |
CVE-2017-11333MEDIUM The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file. | Jul 31, 2017 | 5.5 | 25 | NO | YES |
CVE-2008-1420MEDIUM Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG fi | May 16, 2008 | 6.8 | 24 | NO | NO |
CVE-2020-20412MEDIUM lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE- | Dec 26, 2020 | 6.5 | 22 | NO | NO |
CVE-2017-14633MEDIUM In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted au | Sep 21, 2017 | 6.5 | 22 | NO | NO |
CVE-2008-2009MEDIUM Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file th | May 16, 2008 | 4.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Libvorbis
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.3.6 | 2 | 8.2 | 2.9% | 0 | 0 |
| 1.3.5 | 4 | 7.7 | 4.3% | 0 | 1 |
| 1.2.0 | 3 | 6.8 | 6.2% | 0 | 0 |
| 1.1.2 | 1 | 9.3 | 8.1% | 0 | 0 |
| 1.12 | 2 | 5.5 | 5.3% | 0 | 0 |
| 1.1.1 | 3 | 6.8 | 6.2% | 0 | 0 |
| 1.1.0 | 3 | 6.8 | 6.2% | 0 | 0 |
| 1.0.1 | 3 | 6.8 | 6.2% | 0 | 0 |
| 1.0.0 | 3 | 6.8 | 6.2% | 0 | 0 |
| 1.0 | 1 | 4.3 | 3.5% | 0 | 0 |