Webmproject
Webmproject Libwebp: vulnerabilidades y CVE
Webmproject Libwebp tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas10
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-4863 | Alta (8.8) | 100% | ⚠ Explotación activa | 12 sept 2023 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-4863 | Alta (8.8) | 100% | ⚠ Explotación activa | 12 sept 2023 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:… |
| CVE-2023-1999 | Alta (7.5) | 0.95% | — | 20 jun 2023 | There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because… |
| CVE-2020-36332 | Alta (7.5) | 2.0% | — | 21 may 2021 | A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability. |
| CVE-2020-36331 | Crítica (9.1) | 2.3% | — | 21 may 2021 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability. |
| CVE-2020-36330 | Crítica (9.1) | 2.2% | — | 21 may 2021 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service… |
| CVE-2020-36329 | Crítica (9.8) | 2.3% | — | 21 may 2021 | A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as… |
| CVE-2020-36328 | Crítica (9.8) | 2.7% | — | 21 may 2021 | A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data… |
| CVE-2018-25014 | Crítica (9.8) | 2.2% | — | 21 may 2021 | A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). |
| CVE-2018-25013 | Crítica (9.1) | 2.1% | — | 21 may 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). |
| CVE-2018-25012 | Crítica (9.1) | 2.1% | — | 21 may 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). |
| CVE-2018-25011 | Crítica (9.8) | 2.5% | — | 21 may 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). |
| CVE-2018-25010 | Crítica (9.1) | 2.2% | — | 21 may 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). |
| CVE-2018-25009 | Crítica (9.1) | 2.1% | — | 21 may 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). |
| CVE-2016-9969 | Alta (7.5) | 1.4% | — | 23 may 2019 | In libwebp 0.5.1, there is a double free bug in libwebpmux. |
| CVE-2016-9085 | Baja (3.3) | 0.43% | — | 3 feb 2017 | Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.