<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:13:57 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:5941 — Moderate: libvpx security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:5941</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libvpx, AlmaLinux:8: libvpx-devel&lt;/p&gt;
&lt;p&gt;The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libvpx: Heap buffer overflow related to VP9 encoding (CVE-2023-6349)
* libvpx: Integer overflow in vpx_img_alloc() (CVE-2024-5197)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libvpx, AlmaLinux:8: libvpx-devel&lt;/p&gt;
&lt;p&gt;The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libvpx: Heap buffer overflow related to VP9 encoding (CVE-2023-6349)
* libvpx: Integer overflow in vpx_img_alloc() (CVE-2024-5197)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:5941</guid>
    </item>
    <item>
      <title>bdu:2024-04531</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04531</link>
      <description>bdu:2024-04531</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04531</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0903 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0903</link>
      <description>certfr-2024-avi-0903</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0903</guid>
    </item>
    <item>
      <title>EUVD-2026-217478</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217478</link>
      <description>EUVD-2026-217478</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217478</guid>
    </item>
    <item>
      <title>fkie_cve-2024-5197</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-5197</link>
      <description>&lt;p&gt;There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-5197</guid>
    </item>
    <item>
      <title>GHSA-4h58-f788-v8pw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4h58-f788-v8pw</link>
      <description>&lt;p&gt;There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4h58-f788-v8pw</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-5197 — Integer overflow in libvpx</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-5197</link>
      <description>msrc_CVE-2024-5197</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-5197</guid>
    </item>
    <item>
      <title>OESA-2024-1716 — libvpx security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1716</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libvpx, openEuler:22.03-LTS-SP1: libvpx, openEuler:22.03-LTS-SP3: libvpx, openEuler:24.03-LTS: libvpx&lt;/p&gt;
&lt;p&gt;libvpx provides the VP8/VP9 SDK, which allows you to integrate your applications with the VP8 and VP9 video codecs, high quality, royalty free, open source codecs deployed on millions of computers and devices worldwide.&#13;
&#13;
Security Fix(es):&#13;
&#13;
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond(CVE-2024-5197)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libvpx, openEuler:22.03-LTS-SP1: libvpx, openEuler:22.03-LTS-SP3: libvpx, openEuler:24.03-LTS: libvpx&lt;/p&gt;
&lt;p&gt;libvpx provides the VP8/VP9 SDK, which allows you to integrate your applications with the VP8 and VP9 video codecs, high quality, royalty free, open source codecs deployed on millions of computers and devices worldwide.&#13;
&#13;
Security Fix(es):&#13;
&#13;
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond(CVE-2024-5197)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1716</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14100-1 — libvpx-devel-1.14.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14100-1</link>
      <description>&lt;p&gt;libvpx-devel-1.14.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libvpx-devel-1.14.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14100-1</guid>
    </item>
    <item>
      <title>RHSA-2025:14138 — Red Hat Security Advisory: libvpx security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:14138</link>
      <description>&lt;p&gt;libvpx: Integer overflow in vpx_img_alloc()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libvpx: Integer overflow in vpx_img_alloc()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:14138</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-5197</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-5197</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libvpx, Ubuntu:Pro:16.04:LTS: libvpx, Ubuntu:Pro:18.04:LTS: libvpx, Ubuntu:20.04:LTS: libvpx, Ubuntu:22.04:LTS: libvpx, Ubuntu:24.04:LTS: libvpx&lt;/p&gt;
&lt;p&gt;There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libvpx, Ubuntu:Pro:16.04:LTS: libvpx, Ubuntu:Pro:18.04:LTS: libvpx, Ubuntu:20.04:LTS: libvpx, Ubuntu:22.04:LTS: libvpx, Ubuntu:24.04:LTS: libvpx&lt;/p&gt;
&lt;p&gt;There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-5197</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1945 — Red Hat Enterprise Linux (libvpx): Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1945</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Komponente libvpx ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Komponente libvpx ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1945</guid>
    </item>
  </channel>
</rss>
