x
xiph
Security Risk Profile
30
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 23 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 8, 2007 to present
23
Total CVEs
8
Critical+High
0
Exploited
4
Unpatched
Threat Assessment
Avg CVSS
5.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
30/100
low
Severity Distribution
Critical
3High
5Medium
12Low
2Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Buffer Overflow
11
2
Null Pointer Dereference
2
3
Integer Overflow
2
4
Divide by Zero
1
5
Input Validation
1
Most Affected Products
1. xiph Speex19
2. xine Xine-lib13
3. xiph Libfishsound10
4. Fedoraproject Fedora8
5. openSUSE openSUSE8
Recent Vulnerabilities
See more →CVE-2026-5673
CVSS 7.1EPSS 0%high
Libtheora: libtheora: denial of service or information disclosure via malformed avi file processing
Apr 6, 2026🔧 No Patch
https://seclists.org/oss-sec/2025/q2/95
unknown
CVE-2024-56431: libtheora: incorct bitwise shift in huffdec.c
Apr 25, 2025🔧 No Patch
CVE-2024-56431
CVSS 9.8critical
libtheora: incorct bitwise shift in huffdec.c
Dec 25, 2024🔧 No Patch
REDHAT-BUG-2242151
CVSS 4.0medium
Oct 4, 2023🔧 No Patch
CVE-2023-43361
CVSS 7.8high
Oct 2, 2023🔧 No Patch
CVE-2022-47021
CVSS 7.8high
Jan 20, 2023
CVE-2020-23904
CVSS 5.5medium
Nov 10, 2021🔧 No Patch
CVE-2020-23903
CVSS 5.5medium
Nov 10, 2021
CVE-2018-18820
CVSS 8.1high
Nov 5, 2018
REDHAT-BUG-1574193
CVSS 1.0low
May 2, 2018🔧 No Patch
Monitor xiph in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.