← back
CVE-2024-1580

Integer overflow in VideoLAN dav1d

CVSS 5.9 MEDIUMEPSS 1.8%CWE-190
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 1.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
Affected products
VideoLAN · dav1d

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →