CVE-2019-9746: Webmproject Libwebm

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger an abort, which allows a DoS attack, a similar issue to CVE-2018-19212.

Affected products

Published 2019-03-13. Last modified 2026-06-17.