VulnSea

aom-main vulnerabilities

CVEs whose affected-version data names the aom-main package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-56211High· 7.1
3mo ago

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted vide…

TwilightRed Hat · aomEPSS 0.48%via NVD
CVE-2026-56210High· 7.1
3mo ago

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the co…

TwilightRed Hat · aomEPSS 0.31%via NVD
CVE-2026-56209High· 7.1
3mo ago

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer i…

TwilightRed Hat · aomEPSS 0.35%via NVD
CVE-2026-56208High· 7.6
3mo ago

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when …

TwilightRed Hat · firefoxEPSS 0.42%via NVD
aom-main vulnerabilities (CVEs) · VulnSea