WebM Project libwebp 1.2.3

CPE Details

WebM Project libwebp 1.2.3
1.2.3
2023-07-03
14h39 +00:00
2023-07-05
13h46 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:webmproject:libwebp:1.2.3:-:*:*:*:*:*:*

Informations

Vendor

webmproject

Product

libwebp

Version

1.2.3

Update

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-4863 2023-09-12 14h24 +00:00 Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
8.8
High
CVE-2023-1999 2023-06-20 11h28 +00:00 There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.
7.5
High