<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:14:37.828753+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:5941</id>
    <title>ALSA-2024:5941 — Moderate: libvpx security update</title>
    <updated>2026-10-03T18:14:37.846196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: libvpx, AlmaLinux:8: libvpx-devel</p>
<p>The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.</p>
<p>Security Fix(es):</p>
<p>* libvpx: Heap buffer overflow related to VP9 encoding (CVE-2023-6349)
* libvpx: Integer overflow in vpx_img_alloc() (CVE-2024-5197)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:5941"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04531</id>
    <title>bdu:2024-04531</title>
    <updated>2026-10-03T18:14:37.846284+00:00</updated>
    <content>bdu:2024-04531</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04531"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0903</id>
    <title>certfr-2024-avi-0903 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T18:14:37.846307+00:00</updated>
    <content>certfr-2024-avi-0903</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-217478</id>
    <title>EUVD-2026-217478</title>
    <updated>2026-10-03T18:14:37.846324+00:00</updated>
    <content>EUVD-2026-217478</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-217478"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-5197</id>
    <title>fkie_cve-2024-5197</title>
    <updated>2026-10-03T18:14:37.846336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-5197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4h58-f788-v8pw</id>
    <title>GHSA-4h58-f788-v8pw</title>
    <updated>2026-10-03T18:14:37.846362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4h58-f788-v8pw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-5197</id>
    <title>msrc_CVE-2024-5197 — Integer overflow in libvpx</title>
    <updated>2026-10-03T18:14:37.846380+00:00</updated>
    <content>msrc_CVE-2024-5197</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-5197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1716</id>
    <title>OESA-2024-1716 — libvpx security update</title>
    <updated>2026-10-03T18:14:37.846396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: libvpx, openEuler:22.03-LTS-SP1: libvpx, openEuler:22.03-LTS-SP3: libvpx, openEuler:24.03-LTS: libvpx</p>
<p>libvpx provides the VP8/VP9 SDK, which allows you to integrate your applications with the VP8 and VP9 video codecs, high quality, royalty free, open source codecs deployed on millions of computers and devices worldwide.

Security Fix(es):

There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond(CVE-2024-5197)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1716"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14100-1</id>
    <title>openSUSE-SU-2024:14100-1 — libvpx-devel-1.14.1-1.1 on GA media</title>
    <updated>2026-10-03T18:14:37.846428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libvpx-devel-1.14.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14100-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:14138</id>
    <title>RHSA-2025:14138 — Red Hat Security Advisory: libvpx security update</title>
    <updated>2026-10-03T18:14:37.846445+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libvpx: Integer overflow in vpx_img_alloc()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:14138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-5197</id>
    <title>UBUNTU-CVE-2024-5197</title>
    <updated>2026-10-03T18:14:37.846461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libvpx, Ubuntu:Pro:16.04:LTS: libvpx, Ubuntu:Pro:18.04:LTS: libvpx, Ubuntu:20.04:LTS: libvpx, Ubuntu:22.04:LTS: libvpx, Ubuntu:24.04:LTS: libvpx</p>
<p>There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-5197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1945</id>
    <title>WID-SEC-W-2024-1945 — Red Hat Enterprise Linux (libvpx): Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T18:14:37.846490+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Komponente libvpx ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1945"/>
  </entry>
</feed>
