A double-free in libwebp could have led to memory corruption and a potentially exploitable crash.
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
A flaw was found in libwebp in versions before 1.0.1 in the way it read the contents of a file without limiting memory allocation.
Reference: https://bugs.chromium.org/p/webp/issues/detail?id=391
In libwebp 0.5.1, there is a double free bug in libwebpmux.