Vulnerability Database

299,749

Total vulnerabilities in the database

CVE-2023-45682

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds read in DECODE macro when var is negative. As it can be seen in the definition of DECODE_RAW a negative var is a valid value. This issue may be used to leak internal memory allocation information.

  • Published: Oct 21, 2023
  • Updated: Oct 27, 2023
  • CVE: CVE-2023-45682
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.1
  • AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

CWEs: