Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2026-56208

3 месяца назад

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2026-56208

3 месяца назад

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-56208

3 месяца назад

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2026-56208

3 месяца назад

A heap buffer overflow vulnerability was found in libaom, the referenc ...

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-mgv2-4j37-m3x6

3 месяца назад

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21061-1

3 месяца назад

Security update for libaom

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3224-1

около 2 месяцев назад

Security update for SVT-AV1, libyuv0, libaom3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2829-1

2 месяца назад

Security update for libaom

EPSS: Низкий
rocky логотип

RLSA-2026:47105

около 2 месяцев назад

Important: firefox security update

EPSS: Низкий
rocky логотип

RLSA-2026:47104

около 1 месяца назад

Important: firefox security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-47105

около 2 месяцев назад

ELSA-2026-47105: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-47104

около 2 месяцев назад

ELSA-2026-47104: firefox security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the referenc ...

CVSS3: 7.6
0%
Низкий
3 месяца назад
github логотип
GHSA-mgv2-4j37-m3x6

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21061-1

Security update for libaom

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3224-1

Security update for SVT-AV1, libyuv0, libaom3

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2829-1

Security update for libaom

2 месяца назад
rocky логотип
RLSA-2026:47105

Important: firefox security update

около 2 месяцев назад
rocky логотип
RLSA-2026:47104

Important: firefox security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-47105

ELSA-2026-47105: firefox security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-47104

ELSA-2026-47104: firefox security update (IMPORTANT)

около 2 месяцев назад

Уязвимостей на страницу