Search CVE reports
1 – 10 of 16 results
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate of CVE-2023-4863.
1 affected package
libwebp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libwebp | — | Not affected | Not affected | Not affected |
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
4 affected packages
chromium-browser, libwebp, firefox, thunderbird
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Not affected | Not affected | Not in release | Ignored |
libwebp | Fixed | Fixed | Fixed | Fixed |
firefox | Not affected | Not affected | Fixed | Ignored |
thunderbird | Fixed | Fixed | Fixed | Ignored |
Some fixes available 10 of 26
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out...
8 affected packages
libwebp, firefox, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libwebp | Fixed | Fixed | Fixed | Fixed |
firefox | Not affected | Not affected | Not in release | Not affected |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
thunderbird | Ignored | Ignored | Not in release | Ignored |
Some fixes available 12 of 13
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
1 affected package
libwebp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libwebp | Fixed | Fixed | Fixed | Fixed |
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
1 affected package
libwebp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libwebp | — | Fixed | Fixed | Fixed |
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.
1 affected package
libwebp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libwebp | — | Fixed | Fixed | Fixed |
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
1 affected package
libwebp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libwebp | — | Fixed | Fixed | Fixed |
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to...
1 affected package
libwebp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libwebp | — | Fixed | Fixed | Fixed |
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
1 affected package
libwebp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libwebp | — | Fixed | Fixed | Fixed |
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
1 affected package
libwebp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libwebp | — | Fixed | Fixed | Fixed |