CVE-2020-21722

HIGH

ogg_video_tools 0.9.1 - Use-After-Free via Crafted OGG File

Title source: llm
STIX 2.1

Description

Buffer Overflow vulnerability in oggvideotools 0.9.1 allows remote attackers to run arbitrary code via opening of crafted ogg file.

Scores

CVSS v3 7.8
EPSS 0.0066
EPSS Percentile 47.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (1)
ogg_video_tools_project/ogg_video_tools 0.9.1
Published Aug 22, 2023
Tracked Since Feb 18, 2026