« Volver al listado

Webmproject

Webmproject Libwebp: vulnerabilidades y CVE

Webmproject Libwebp tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE15
Últimos 12 meses0
Críticas10
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-4863Alta (8.8)100%⚠ Explotación activa12 sept 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-4863Alta (8.8)100%⚠ Explotación activa12 sept 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:…
CVE-2023-1999Alta (7.5)0.95%—20 jun 2023
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because…
CVE-2020-36332Alta (7.5)2.0%—21 may 2021
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
CVE-2020-36331Crítica (9.1)2.3%—21 may 2021
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
CVE-2020-36330Crítica (9.1)2.2%—21 may 2021
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service…
CVE-2020-36329Crítica (9.8)2.3%—21 may 2021
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as…
CVE-2020-36328Crítica (9.8)2.7%—21 may 2021
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data…
CVE-2018-25014Crítica (9.8)2.2%—21 may 2021
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
CVE-2018-25013Crítica (9.1)2.1%—21 may 2021
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
CVE-2018-25012Crítica (9.1)2.1%—21 may 2021
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
CVE-2018-25011Crítica (9.8)2.5%—21 may 2021
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
CVE-2018-25010Crítica (9.1)2.2%—21 may 2021
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
CVE-2018-25009Crítica (9.1)2.1%—21 may 2021
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
CVE-2016-9969Alta (7.5)1.4%—23 may 2019
In libwebp 0.5.1, there is a double free bug in libwebpmux.
CVE-2016-9085Baja (3.3)0.43%—3 feb 2017
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Webmproject