Known vulnerabilities in libvpx (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:libvpx_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 8
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libvpx (Debian package) libvpx (Debian package) is affected by 8 known vulnerabilities: 1 critical, 2 high, 1 medium, 4 low Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU122970 - Heap-based Buffer Overflow
CVE-2026-2447
CWE-122 High
No
No
1.12.0-1+deb12u5, 1.15.0-2.1+deb13u1 16.02.2026 SB20260216163
SB20260216169
SB2026022003
and 43 more
#VU109870 - Use After Free
CVE-2025-5283
CWE-416 Medium
No
No
1.12.0-1+deb12u4 27.05.2025 SB2025052766
SB2025052901
SB20250529172
and 22 more
#VU90121 - Integer overflow
CVE-2024-5197
CWE-190 High
No
No
1.9.0-1+deb11u3, 1.12.0-1+deb12u3 31.05.2024 SB2024053145
SB2024060640
SB2024061506
and 14 more
#VU81244 - Heap-based Buffer Overflow
CVE-2023-5217
CWE-122 Critical
Available
Exploited
1.9.0-1+deb11u1, 1.9.0-1+deb11u2, 1.12.0-1+deb12u1, 1.12.0-1+deb12u2 27.09.2023 SB2023092804
SB2023092847
SB2023092851
and 101 more
#VU23106 - Resource exhaustion
CVE-2019-9371
CWE-400 Low
No
No
1.6.1-3+deb9u2, 1.7.0-3+deb10u1 29.11.2019 SB2019092728
SB2019112910
SB2020012713
and 5 more
#VU23105 - Improper input validation
CVE-2019-9433
CWE-20 Low
No
No
1.6.1-3+deb9u2, 1.7.0-3+deb10u1 29.11.2019 SB2019092728
SB2019112910
SB2020012713
and 7 more
#VU23104 - Out-of-bounds read
CVE-2019-9325
CWE-125 Low
No
No
1.6.1-3+deb9u2, 1.7.0-3+deb10u1 29.11.2019 SB2019092728
SB2019112910
SB2020012713
and 4 more
#VU23103 - Out-of-bounds read
CVE-2019-9232
CWE-125 Low
No
No
1.6.1-3+deb9u2, 1.7.0-3+deb10u1 29.11.2019 SB2019092728
SB2019112910
SB2020012713
and 7 more