Loading
Generated remediation guidance and an executive summary. No account required.
VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an out-of-bounds read, related to "the clamping of motion vectors in SPLITMV blocks".
Use CWE-20, Webmproject vendor hub and Libvpx product page to widen CVE-2012-0823 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-5217, CVE-2010-4203 and CVE-2023-44488 for nearby disclosures in the same product family.