webmproject CVE Vulnerabilities & Metrics

Focus on webmproject vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About webmproject Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with webmproject. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total webmproject CVEs: 21
Earliest CVE date: 06 Nov 2010, 00:00 UTC
Latest CVE date: 30 Sep 2023, 20:15 UTC

Latest CVE reference: CVE-2023-44488

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical webmproject CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.18

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 12
7.0-8.9 5
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS webmproject CVEs

These are the five CVEs with the highest CVSS scores for webmproject, sorted by severity first and recency.

All CVEs for webmproject

CVE-2023-44488 webmproject vulnerability CVSS: 0 30 Sep 2023, 20:15 UTC

VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.

CVE-2023-5217 webmproject vulnerability CVSS: 0 28 Sep 2023, 16:15 UTC

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-4863 webmproject vulnerability CVSS: 0 12 Sep 2023, 15:15 UTC

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVE-2023-1999 webmproject vulnerability CVSS: 0 20 Jun 2023, 12:15 UTC

There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.

CVE-2020-36332 webmproject vulnerability CVSS: 5.0 21 May 2021, 17:15 UTC

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.

CVE-2020-36331 webmproject vulnerability CVSS: 6.4 21 May 2021, 17:15 UTC

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVE-2020-36330 webmproject vulnerability CVSS: 6.4 21 May 2021, 17:15 UTC

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVE-2020-36329 webmproject vulnerability CVSS: 7.5 21 May 2021, 17:15 UTC

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-36328 webmproject vulnerability CVSS: 7.5 21 May 2021, 17:15 UTC

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2018-25014 webmproject vulnerability CVSS: 7.5 21 May 2021, 17:15 UTC

A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

CVE-2018-25013 webmproject vulnerability CVSS: 6.4 21 May 2021, 17:15 UTC

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

CVE-2018-25012 webmproject vulnerability CVSS: 6.4 21 May 2021, 17:15 UTC

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

CVE-2018-25011 webmproject vulnerability CVSS: 7.5 21 May 2021, 17:15 UTC

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().

CVE-2018-25010 webmproject vulnerability CVSS: 6.4 21 May 2021, 17:15 UTC

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().

CVE-2018-25009 webmproject vulnerability CVSS: 6.4 21 May 2021, 17:15 UTC

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().

CVE-2016-9969 webmproject vulnerability CVSS: 5.1 23 May 2019, 18:29 UTC

In libwebp 0.5.1, there is a double free bug in libwebpmux.

CVE-2019-9746 webmproject vulnerability CVSS: 5.0 13 Mar 2019, 16:29 UTC

In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger an abort, which allows a DoS attack, a similar issue to CVE-2018-19212.

CVE-2018-19212 webmproject vulnerability CVSS: 4.3 12 Nov 2018, 19:29 UTC

In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack.

CVE-2018-6548 webmproject vulnerability CVSS: 7.5 02 Feb 2018, 09:29 UTC

A use-after-free issue was discovered in libwebm through 2018-02-02. If a Vp9HeaderParser was initialized once before, its property frame_ would not be changed because of code in vp9parser::Vp9HeaderParser::SetFrame. Its frame_ could be freed while the corresponding pointer would not be updated, leading to a dangling pointer. This is related to the function OutputCluster in webm_info.cc.

CVE-2018-6406 webmproject vulnerability CVSS: 6.8 30 Jan 2018, 21:29 UTC

The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data obtained from a .webm file, which allows remote attackers to cause an information leak or a denial of service (heap-based buffer over-read and later out-of-bounds write), or possibly have unspecified other impact.

CVE-2016-9085 webmproject vulnerability CVSS: 2.1 03 Feb 2017, 15:59 UTC

Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.

CVE-2012-0823 webmproject vulnerability CVSS: 5.0 23 Feb 2012, 20:07 UTC

VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an out-of-bounds read, related to "the clamping of motion vectors in SPLITMV blocks".

CVE-2010-4203 webmproject vulnerability CVSS: 10.0 06 Nov 2010, 00:00 UTC

WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.