CVE-2023-6349

A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1 or above
References
Link Resource
https://crbug.com/webm/1642 Exploit Issue Tracking
https://crbug.com/webm/1642 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:webmproject:libvpx:*:*:*:*:*:*:*:*

History

22 Jul 2025, 20:08

Type Values Removed Values Added
CPE cpe:2.3:a:webmproject:libvpx:*:*:*:*:*:*:*:*
First Time Webmproject libvpx
Webmproject
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://crbug.com/webm/1642 - () https://crbug.com/webm/1642 - Exploit, Issue Tracking

Information

Published : 2024-05-27 12:15

Updated : 2025-07-22 20:08


NVD link : CVE-2023-6349

Mitre link : CVE-2023-6349

CVE.ORG link : CVE-2023-6349


JSON object : View

Products Affected

webmproject

  • libvpx
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write