Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 354 respecto a la semana anterior
Críticas / altas1295▼ 24 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.64% | — | STB VorbisAI | 11/9/2026 | 24/9/2026 | stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap… | |
| Analizada | Baja (2.1) | 0.59% | — | Nothings STB Vorbis.c | 2/4/2026 | 17/6/2026 | A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in out-of-bounds write. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted… | |
| Analizada | Baja (2.1) | 0.72% | — | Nothings STB Vorbis.c | 2/4/2026 | 17/6/2026 | A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation leads to allocation of resources. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early… | |
| Modificada | Crítica (9.8) | 1.4% | — | Nothings STB Vorbis.cFedoraproject Fedora | 1/5/2024 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.1) | 0.56% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds read in `DECODE` macro when `var` is negative. As it can be seen in the definition of `DECODE_RAW` a negative `var` is a valid value. This issue may be used to leak internal memory allocation… | |
| Modificada | Alta (7.8) | 0.52% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory write past an allocated heap buffer in `start_decoder`. The root cause is a potential integer overflow in `sizeof(char*) * (f->comment_list_length)` which may make `setup_malloc` allocate less memory… | |
| Modificada | Media (5.5) | 0.53% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, the `f->comment_list` is set to `NULL`, but `f->comment_list_length` is not reset. Later in `vorbis_deinit` it tries to… | |
| Modificada | Alta (7.8) | 0.52% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, but some of the pointers in `f->comment_list` are left initialized and later `setup_free` is called on these pointers in… | |
| Modificada | Alta (7.8) | 0.73% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buffer write in `start_decoder` because at maximum `m->submaps` can be 16 but `submap_floor` and `submap_residue` are declared as arrays of 15 elements. This issue may lead to code execution. | |
| Modificada | Alta (7.8) | 0.54% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in `f->vendor[len] = (char)'\0';`. The root cause is that if `len` read in `start_decoder` is a negative number and `setup_malloc` successfully allocates memory in that case, but memory… | |
| Modificada | Alta (7.8) | 0.52% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in `f->vendor[i] = get8_packet(f);`. The root cause is an integer overflow in `setup_malloc`. A sufficiently large value in the variable `sz` overflows with `sz+7` in and the negative value… | |
| Modificada | Alta (7.8) | 0.76% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in `f->vendor[len] = (char)'\0';`. The root cause is that if the len read in `start_decoder` is `-1` and `len + 1` becomes 0 when passed to `setup_malloc`. The `setup_malloc` behaves… | |
| Modificada | Media (5.5) | 0.96% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. | |
| Modificada | Alta (7.1) | 0.98% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file. | |
| Modificada | Alta (7.8) | 1.5% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file. | |
| Modificada | Alta (7.1) | 0.98% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file. | |
| Modificada | Media (5.5) | 0.96% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. | |
| Modificada | Media (5.5) | 1.0% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. | |
| Modificada | Alta (7.8) | 1.5% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file. | |
| Modificada | Alta (8.8) | 1.8% | — | STB Vorbis Project STB Vorbis | 9/2/2018 | 17/6/2026 | Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. that can result in memory corruption, denial of service, comprised execution of host program. This attack appear to be exploitable via Victim must open a specially crafted Ogg Vorbis file. This… |