vciy

CVEs we hold for Nothings

Records whose assigning authority named Nothings as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-89266stb_vorbis through 1.22 heap buffer overflow via codebook multiplicandsnothings stb_vorbis
CVE-2026-5317Nothings stb stb_vorbis.c start_decoder out-of-bounds writeNothings stb
CVE-2026-5316Nothings stb stb_vorbis.c setup_free allocation of resourcesNothings stb
CVE-2026-5315Nothings stb TTF File stb_truetype.h stbtt__buf_get8 out-of-boundsNothings stb
CVE-2026-5314Nothings stb TTF File stb_truetype.h stbtt_InitFont_internal out-of-boundsNothings stb
CVE-2026-5313Nothings stb GIF Decoder stb_image.h stbi__gif_load_next denial of serviceNothings stb
CVE-2026-5186Nothings stb Multi-frame GIF File stb_image.h stbi__load_gif_main double freeNothings stb
CVE-2026-5185Nothings stb_image Multi-frame GIF File stb_image.h stbi__gif_load_next heap-based overflowNothings stb_image
CVE-2025-3409Nothings stb stb_include_string stack-based overflowNothings stb
CVE-2025-3408Nothings stb stb_dupreplace integer overflowNothings stb
CVE-2025-3407Nothings stb stbhw_build_tileset_from_image out-of-boundsNothings stb
CVE-2025-3406Nothings stb Header Array stbhw_build_tileset_from_image out-of-boundsNothings stb
CVE-2023-45682Wild address read in vorbis_decode_packet_rest in stb_vorbisnothings stb
CVE-2023-45681Out of bounds heap buffer write in stb_vorbisnothings stb
CVE-2023-45680Null pointer dereference in vorbis_deinit in stb_vorbisnothings stb
CVE-2023-45679Attempt to free an uninitialized memory pointer in vorbis_deinit in stb_vorbisnothings stb
CVE-2023-45678Off-by-one heap buffer write in start_decoder in stb_vorbisnothings stb
CVE-2023-45677Heap buffer out of bounds write in start_decoder in stb_vorbisnothings stb
CVE-2023-45676Multi-byte write heap buffer overflow in start_decoder in stb_vorbisnothings stb
CVE-2023-456750 byte write heap buffer overflow in start_decoder in stb_vorbisnothings stb
CVE-2023-45667Null pointer dereference because of an uninitialized variable in stb_imagenothings stb
CVE-2023-45666Possible double-free or memory leak in stbi__load_gif_main in stb_imagenothings stb
CVE-2023-45664Double-free in stbi__load_gif_main_outofmem in stb_imagenothings stb
CVE-2023-45663Disclosure of uninitialized memory in stbi__tga_load in stb_imagenothings stb
CVE-2023-45662Multi-byte read heap buffer overflow in stbi__vertical_flip in stb_imagenothings stb
CVE-2023-45661Wild address read in stbi__gif_load_next in stb_imagenothings stb

26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.