Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:videolan:dav1d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B21FACDB-790F-4BDF-AE54-72C70D1880C0", "versionEndExcluding": "1.4.0", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*", "matchCriteriaId": "5B0BD32E-FA45-4796-956D-D1F2C049171E", "versionEndExcluding": "17.4.1", "vulnerable": true}, {"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*", "matchCriteriaId": "35B07242-1592-4814-8866-FA7DA2021DDC", "versionEndExcluding": "16.7.7", "vulnerable": true}, {"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*", "matchCriteriaId": "027265B2-C0CD-46D8-BF40-5E591CFDE9D6", "versionEndExcluding": "17.4.1", "versionStartIncluding": "17.0", "vulnerable": true}, {"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*", "matchCriteriaId": "4450D591-7B62-4339-9F0F-08C51F701967", "versionEndExcluding": "16.7.7", "vulnerable": true}, {"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*", "matchCriteriaId": "9AA95646-94B7-4C20-9B69-371409BA4E22", "versionEndExcluding": "17.4.1", "versionStartIncluding": "17.0", "vulnerable": true}, {"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*", "matchCriteriaId": "55A1512B-3C9A-428C-97BD-B3B6813B150D", "versionEndExcluding": "13.6.6", "versionStartIncluding": "13.0", "vulnerable": true}, {"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*", "matchCriteriaId": "580B86E1-BCC1-419C-86B7-2A33DA257401", "versionEndExcluding": "14.4.1", "versionStartIncluding": "14.0", "vulnerable": true}, {"criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*", "matchCriteriaId": "C8418E27-11BA-4DE1-9596-6E88F5A9C052", "versionEndExcluding": "1.1.1", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*", "matchCriteriaId": "CA277A6C-83EC-4536-9125-97B84C4FAF59", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d."}, {"lang": "es", "value": "Un desbordamiento de enteros en el decodificador dav1d AV1 que puede ocurrir al decodificar videos con un tama\u00f1o de cuadro grande. Esto puede provocar da\u00f1os en la memoria del decodificador AV1. Recomendamos actualizar la versi\u00f3n anterior 1.4.0 de dav1d."}], "id": "CVE-2024-1580", "lastModified": "2025-02-13T18:16:25.577", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "HIGH", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "LOW", "baseScore": 5.9, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L", "version": "3.1"}, "exploitabilityScore": 1.2, "impactScore": 4.7, "source": "cve-coordination@google.com", "type": "Secondary"}, {"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2024-02-19T11:15:08.817", "references": [{"source": "cve-coordination@google.com", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/36"}, {"source": "cve-coordination@google.com", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/37"}, {"source": "cve-coordination@google.com", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/38"}, {"source": "cve-coordination@google.com", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/39"}, {"source": "cve-coordination@google.com", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/40"}, {"source": "cve-coordination@google.com", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/41"}, {"source": "cve-coordination@google.com", "tags": ["Release Notes"], "url": "https://code.videolan.org/videolan/dav1d/-/blob/master/NEWS"}, {"source": "cve-coordination@google.com", "tags": ["Release Notes"], "url": "https://code.videolan.org/videolan/dav1d/-/releases/1.4.0"}, {"source": "cve-coordination@google.com", "tags": ["Mailing List"], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/"}, {"source": "cve-coordination@google.com", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214093"}, {"source": "cve-coordination@google.com", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214094"}, {"source": "cve-coordination@google.com", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214095"}, {"source": "cve-coordination@google.com", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214096"}, {"source": "cve-coordination@google.com", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214097"}, {"source": "cve-coordination@google.com", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214098"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/36"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/37"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/38"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/39"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/40"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Mailing List"], "url": "http://seclists.org/fulldisclosure/2024/Mar/41"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Release Notes"], "url": "https://code.videolan.org/videolan/dav1d/-/blob/master/NEWS"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Release Notes"], "url": "https://code.videolan.org/videolan/dav1d/-/releases/1.4.0"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Mailing List"], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214093"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214094"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214095"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214096"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214097"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory"], "url": "https://support.apple.com/kb/HT214098"}], "sourceIdentifier": "cve-coordination@google.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-190"}], "source": "cve-coordination@google.com", "type": "Secondary"}, {"description": [{"lang": "en", "value": "CWE-190"}], "source": "nvd@nist.gov", "type": "Primary"}]}