Webmproject
Webmproject Libwebp: vulnerabilities and CVEs
Webmproject Libwebp has 15 published vulnerabilities, 0 of them in the last 12 months. 10 are rated critical and 1 are listed by CISA as actively exploited.
CVEs15
Last 12 months0
Critical10
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4863 | High (8.8) | 100% | ⚠ Active exploitation | Sep 12, 2023 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4863 | High (8.8) | 100% | ⚠ Active exploitation | Sep 12, 2023 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:… |
| CVE-2023-1999 | High (7.5) | 0.95% | — | Jun 20, 2023 | There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because… |
| CVE-2020-36332 | High (7.5) | 2.0% | — | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability. |
| CVE-2020-36331 | Critical (9.1) | 2.3% | — | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability. |
| CVE-2020-36330 | Critical (9.1) | 2.2% | — | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service… |
| CVE-2020-36329 | Critical (9.8) | 2.3% | — | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as… |
| CVE-2020-36328 | Critical (9.8) | 2.7% | — | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data… |
| CVE-2018-25014 | Critical (9.8) | 2.2% | — | May 21, 2021 | A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). |
| CVE-2018-25013 | Critical (9.1) | 2.1% | — | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). |
| CVE-2018-25012 | Critical (9.1) | 2.1% | — | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). |
| CVE-2018-25011 | Critical (9.8) | 2.5% | — | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). |
| CVE-2018-25010 | Critical (9.1) | 2.2% | — | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). |
| CVE-2018-25009 | Critical (9.1) | 2.1% | — | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). |
| CVE-2016-9969 | High (7.5) | 1.4% | — | May 23, 2019 | In libwebp 0.5.1, there is a double free bug in libwebpmux. |
| CVE-2016-9085 | Low (3.3) | 0.43% | — | Feb 3, 2017 | Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.