Vendor
A heap-based buffer overflow in the stb_vorbis library allows for arbitrary code execution via a maliciously crafted Ogg Vorbis audio file.