These are all security issues fixed in the libvpx-devel-1.10.0-1.3 package on the GA media of openSUSE Tumbleweed.
{ "binaries": [ { "libvpx6": "1.10.0-1.3", "libvpx6-32bit": "1.10.0-1.3", "libvpx-devel": "1.10.0-1.3", "vpx-tools": "1.10.0-1.3" } ] }