Home/Product/aomedia
Product

aomedia

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-48175
< 1.3.0
In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows in multiplications involving rgbRowBytes, yRowBytes
4.5MEDIUM
CVE-2025-48174
< 1.3.0
In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream-offset+size.
4.5MEDIUM
CVE-2024-5171
>= 1.0.0 and <= 3.9.0
Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via
9.8CRITICAL
CVE-2023-6879
< 3.7.1
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_res
9.0CRITICAL
CVE-2023-39616
>= 3.0.0 and <= 3.5.0
AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/co
7.5HIGH
CVE-2020-36135
all versions
AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.
6.5MEDIUM
CVE-2020-36134
all versions
AOM v2.0.1 was discovered to contain a segmentation violation via the component aom_dsp/x86/obmc_sad_avx2.c.
6.5MEDIUM
CVE-2020-36133
all versions
AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h.
8.8HIGH
CVE-2020-36131
all versions
AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c.
8.8HIGH
CVE-2020-36130
all versions
AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c.
6.5MEDIUM
CVE-2020-36129
all versions
AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c.
8.8HIGH
CVE-2020-36407
all versions
libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
8.8HIGH
CVE-2021-30475
< 2021-03-24
aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.
9.8CRITICAL
CVE-2021-30474
< 2021-03-30
aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.
9.8CRITICAL
CVE-2021-30473
< 2021-04-07
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin