← Vulnerability feed

Vulnerability record · CVE-2017-11333 · published 31 July 2017

CVE-2017-11333: Xiph.org libvorbis null pointer dereference vulnerability

XXiph.Org · Libvorbis

The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.

5.5 CVSS 3.0 Medium EPSS 4.8% · top 8.3% CWE-476 · NULL pointer dereference
5.5CVSS 3.0 base score, v2 4.3
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-11333 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-14632Xiph.org libvorbis memory buffer overflow vulnerabilityXiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi…EPSS 5.7%9.3CVE-2008-1423Xiph.org libvorbis vulnerabilityInteger overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial o…EPSS 8.1%8.8CVE-2018-10392Xiph.org libvorbis out-of-bounds read vulnerabilitymapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial …EPSS 3.3%8.8CVE-2017-14160Xiph.org libvorbis memory buffer overflow vulnerabilityThe bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and …EPSS 4.6%7.5CVE-2018-10393Xiph.org libvorbis out-of-bounds read vulnerabilitybark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.EPSS 2.4%6.8CVE-2008-1420Xiph.org libvorbis vulnerabilityInteger overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbi…EPSS 6.3%6.5CVE-2020-20412Stepmania vulnerabilitylib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG fi…EPSS 1.0%6.5CVE-2017-14633Xiph.org libvorbis out-of-bounds read vulnerabilityIn Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2017-11333), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.