<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:03:34 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:2076 — Important: libwebp security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:2076</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libwebp, AlmaLinux:8: libwebp-devel&lt;/p&gt;
&lt;p&gt;The libwebp packages provide a library and tools for the WebP graphics format. WebP is an image format with a lossy compression of digital photographic images. WebP consists of a codec based on the VP8 format, and a container based on the Resource Interchange File Format (RIFF). Webmasters, web developers and browser developers can use WebP to compress, archive, and distribute digital images more efficiently.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Mozilla: libwebp: Double-free in libwebp (CVE-2023-1999)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libwebp, AlmaLinux:8: libwebp-devel&lt;/p&gt;
&lt;p&gt;The libwebp packages provide a library and tools for the WebP graphics format. WebP is an image format with a lossy compression of digital photographic images. WebP consists of a codec based on the VP8 format, and a container based on the Resource Interchange File Format (RIFF). Webmasters, web developers and browser developers can use WebP to compress, archive, and distribute digital images more efficiently.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Mozilla: libwebp: Double-free in libwebp (CVE-2023-1999)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:2076</guid>
    </item>
    <item>
      <title>bdu:2023-02923</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-02923</link>
      <description>bdu:2023-02923</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-02923</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-1999 — CVE-2023-1999 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-1999</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-1999</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0513 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0513</link>
      <description>certfr-2023-avi-0513</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0513</guid>
    </item>
    <item>
      <title>EUVD-2026-216184</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216184</link>
      <description>EUVD-2026-216184</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216184</guid>
    </item>
    <item>
      <title>fkie_cve-2023-1999</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-1999</link>
      <description>&lt;p&gt;There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-1999</guid>
    </item>
    <item>
      <title>GHSA-8x9p-cw2c-6253</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8x9p-cw2c-6253</link>
      <description>&lt;p&gt;There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8x9p-cw2c-6253</guid>
    </item>
    <item>
      <title>gsd-2023-1999</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-1999</link>
      <description>gsd-2023-1999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-1999</guid>
    </item>
    <item>
      <title>OESA-2023-1317 — libwebp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1317</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libwebp, openEuler:20.03-LTS-SP3: libwebp, openEuler:22.03-LTS: libwebp, openEuler:22.03-LTS-SP1: libwebp&lt;/p&gt;
&lt;p&gt;This is an image format that does lossy compression of digital photographic images. WebP consists of a codec based on VP8, and a container based on RIFF. Webmasters, web developers and browser developers can use WebP to compress, archive and distribute digital images more efficiently.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in libwebp (affected version unknown). It has been declared as critical. Affected by this vulnerability is an unknown code of the component Image File Handler. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2023-1999)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libwebp, openEuler:20.03-LTS-SP3: libwebp, openEuler:22.03-LTS: libwebp, openEuler:22.03-LTS-SP1: libwebp&lt;/p&gt;
&lt;p&gt;This is an image format that does lossy compression of digital photographic images. WebP consists of a codec based on VP8, and a container based on RIFF. Webmasters, web developers and browser developers can use WebP to compress, archive and distribute digital images more efficiently.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in libwebp (affected version unknown). It has been declared as critical. Affected by this vulnerability is an unknown code of the component Image File Handler. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2023-1999)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1317</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13019-1 — libsharpyuv0-1.3.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13019-1</link>
      <description>&lt;p&gt;libsharpyuv0-1.3.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsharpyuv0-1.3.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13019-1</guid>
    </item>
    <item>
      <title>RHSA-2023:1785 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1785</link>
      <description>&lt;p&gt;Mozilla: Memory Corruption in Safe Browsing Code Mozilla: libwebp: Double-free in libwebp Mozilla: Fullscreen notification obscured Mozilla: Potential Memory Corruption following Garbage Collector compaction Mozilla: Invalid free from JavaScript code Mozilla: Content-Disposition filename truncation leads to Reflected File Download Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux Mozilla: Incorrect optimization result on ARM64 Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mozilla: Memory Corruption in Safe Browsing Code Mozilla: libwebp: Double-free in libwebp Mozilla: Fullscreen notification obscured Mozilla: Potential Memory Corruption following Garbage Collector compaction Mozilla: Invalid free from JavaScript code Mozilla: Content-Disposition filename truncation leads to Reflected File Download Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux Mozilla: Incorrect optimization result on ARM64 Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1785</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:2552-1 — Security update for libwebp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:2552-1</link>
      <description>&lt;p&gt;Security update for libwebp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libwebp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:2552-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-1999</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1999</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libwebp, Ubuntu:Pro:16.04:LTS: libwebp, Ubuntu:18.04:LTS: libwebp, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: libwebp, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: libwebp, Ubuntu:22.04:LTS: mozjs78 and 5 more&lt;/p&gt;
&lt;p&gt;There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libwebp, Ubuntu:Pro:16.04:LTS: libwebp, Ubuntu:18.04:LTS: libwebp, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: libwebp, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: libwebp, Ubuntu:22.04:LTS: mozjs78 and 5 more&lt;/p&gt;
&lt;p&gt;There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1999</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1133 — Red Hat Enterprise Linux (libwebp): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1133</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux und Oracle Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux und Oracle Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1133</guid>
    </item>
  </channel>
</rss>
