AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-0894

HIGH · CVSS 7.5 EPSS 1.70%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-02-23 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Windows, Linux, Chrome. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2013-0894
Severity
HIGH
CVSS
7.5
EPSS
1.70%
Windows Linux Chrome

Original NVD Description

Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds array access) or possibly have unspecified other impact via vectors involving a zero value for a bark map size.