Loading vulnerability details…
CVSS v3.1
5.9
EPSS
1.84%
Published
Feb 19, 2024
Modified
Feb 13, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:LWeaknesses (CWE)
Affected Products (10)
References (20)