Search

Found 272 results in 42ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2014-9316 high 7.5 FIX debian debian ffmpeg 12y ago The mjpeg_decode_app function in libavcodec/mjpegdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap acc…
CVE-2014-8549 high 7.5 FIX debian debian ffmpeg 12y ago libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of channels to at most 2, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have u…
CVE-2014-8548 high 7.5 FIX debian debianubuntu ubuntu ffmpeg 12y ago Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime…
CVE-2014-8547 high 7.5 FIX debian debianubuntu ubuntu ffmpeg 12y ago libavcodec/gifdec.c in FFmpeg before 2.4.2 does not properly compute image heights, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified othe…
CVE-2014-8546 high 7.5 FIX debian debian ffmpeg 12y ago Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Cine…
CVE-2014-8545 high 7.5 FIX debian debian ffmpeg 12y ago libavcodec/pngdec.c in FFmpeg before 2.4.2 accepts the monochrome-black format without verifying that the bits-per-pixel value is 1, which allows remote attackers to cause a denial of service (out-of…
CVE-2014-8544 high 7.5 FIX debian debianubuntu ubuntu ffmpeg 12y ago libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecifi…
CVE-2014-8543 high 7.5 FIX debian debianubuntu ubuntu ffmpeg 12y ago libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote attackers to cause a denial of service (out-of-bound…
CVE-2014-8542 high 7.5 FIX debian debianubuntu ubuntu ffmpeg 12y ago libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have …
CVE-2014-8541 high 7.5 FIX debian debianubuntu ubuntu ffmpeg 12y ago libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension differences, and not bits-per-pixel differences, when determining whether an image size has changed, which allows remote attacker…
CVE-2014-5272 medium 6.8 FIX debian debian ffmpeg 12y ago libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote attackers to have unspecified impact via a crafted iff image, which triggers an …
CVE-2014-5271 high 7.5 FIX debian debian libavffmpeg 12y ago Heap-based buffer overflow in the encode_slice function in libavcodec/proresenc_kostya.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.x before 2.2.7, and 2.3.x before 2.3.3 and Libav before 10.5 al…
CVE-2014-2099 medium 6.8 FIX debian debian ffmpeg 12y ago The msrle_decode_frame function in libavcodec/msrle.c in FFmpeg before 2.1.4 does not properly calculate line sizes, which allows remote attackers to cause a denial of service (out-of-bounds array ac…
CVE-2014-2098 medium 6.8 FIX debian debian ffmpeg 12y ago libavcodec/wmalosslessdec.c in FFmpeg before 2.1.4 uses an incorrect data-structure size for certain coefficients, which allows remote attackers to cause a denial of service (memory corruption) or po…
CVE-2014-2097 medium 6.8 FIX debian debian ffmpeg 12y ago The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows remote attackers to cause a denial of service (out…
CVE-2014-2263 medium 6.8 FIX debian debian ffmpeg 12y ago The mpegts_write_pmt function in the MPEG2 transport stream (aka DVB) muxer (libavformat/mpegtsenc.c) in FFmpeg, possibly 2.1 and earlier, allows remote attackers to have unspecified impact and vecto…
CVE-2012-6618 low 2.6 FIX debian debian ffmpeg 13y ago The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a craft…
CVE-2012-6617 medium 4.3 FIX debian debian ffmpeg 13y ago The prepare_sdp_description function in ffserver.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (crash) via vectors related to the rtp format.
CVE-2012-6616 medium 5.0 FIX debian debian ffmpeg 13y ago The mov_text_decode_frame function in libavcodec/movtextdec.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via crafted 3GPP TS 26.245 dat…
CVE-2012-6615 medium 4.3 FIX debian debian ffmpeg 13y ago The ff_ass_split_override_codes function in libavcodec/ass_split.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a subtitle dial…
CVE-2013-4358 medium 5.0 FIX debian debian ffmpeg 13y ago libavcodec/h264.c in FFmpeg before 0.11.4 allows remote attackers to cause a denial of service (crash) via vectors related to alternating bit depths in H.264 data.
CVE-2013-7024 medium 6.8 FIX debian debian ffmpeg 13y ago The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not consider the component number in certain calculations, which allows remote attackers to cause a denial of s…
CVE-2013-7023 medium 6.8 FIX debian debian ffmpeg 13y ago The ff_combine_frame function in libavcodec/parser.c in FFmpeg before 2.1 does not properly handle certain memory-allocation errors, which allows remote attackers to cause a denial of service (out-of…
CVE-2013-7022 medium 6.8 FIX debian debian ffmpeg 13y ago The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 does not properly allocate memory for tiles, which allows remote attackers to cause a denial of service (out-of-bounds array …
CVE-2013-7021 medium 6.8 FIX debian debian ffmpeg 13y ago The filter_frame function in libavfilter/vf_fps.c in FFmpeg before 2.1 does not properly ensure the availability of FIFO content, which allows remote attackers to cause a denial of service (double fr…
CVE-2013-7020 medium 6.8 FIX debian debian ffmpeg 13y ago The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of servic…
CVE-2013-7019 medium 6.8 FIX debian debian ffmpeg 13y ago The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers to cause a denial of service (out-of-bounds array …
CVE-2013-7018 medium 6.8 FIX debian debian ffmpeg 13y ago libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the use of valid code-block dimension values, which allows remote attackers to cause a denial of service (out-of-bounds array access) or …
CVE-2013-7017 medium 6.8 FIX debian debian ffmpeg 13y ago libavcodec/jpeg2000.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via crafted JPEG2000 data.
CVE-2013-7016 medium 6.8 FIX debian debian ffmpeg 13y ago The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the expected sample separation, which allows remote attackers to cause a denial of service (out-of-bounds array a…
CVE-2013-7015 medium 6.8 FIX debian debian ffmpeg 13y ago The flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before 2.1 does not properly validate a certain height value, which allows remote attackers to cause a denial of service (out-of-bo…
CVE-2013-7014 medium 6.8 FIX debian debian ffmpeg 13y ago Integer signedness error in the add_bytes_l2_c function in libavcodec/pngdsp.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have …
CVE-2013-7013 medium 6.8 FIX debian debian ffmpeg 13y ago The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote attackers to cause a denial of service (out-of-bound…
CVE-2013-7012 medium 6.8 FIX debian debian ffmpeg 13y ago The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not prevent attempts to use non-zero image offsets, which allows remote attackers to cause a denial of service (out-of-bound…
CVE-2013-7011 medium 6.8 FIX debian debian ffmpeg 13y ago The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not prevent changes to global parameters, which allows remote attackers to cause a denial of service (out-of-bounds array ac…
CVE-2013-7010 medium 6.8 FIX debian debian ffmpeg 13y ago Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other imp…
CVE-2013-7009 medium 6.8 FIX debian debian ffmpeg 13y ago The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows remote attackers to cause a denial of service (out-of-bounds…
CVE-2013-7008 medium 6.8 FIX debian debian ffmpeg 13y ago The decode_slice_header function in libavcodec/h264.c in FFmpeg before 2.1 incorrectly relies on a certain droppable field, which allows remote attackers to cause a denial of service (deadlock) or po…
CVE-2011-4351 high 7.5 FIX debian debian ffmpeg 13y ago Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before 0.7.8, and 0.8.x before 0.8.8 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2011-3950 medium 6.8 FIX debian debian ffmpeg 13y ago The dirac_decode_data_unit function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via a crafted value in the reference pictures number.
CVE-2011-3949 medium 6.8 FIX debian debian ffmpeg 13y ago The dirac_unpack_idwt_params function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Dirac data.
CVE-2011-3946 medium 6.8 FIX debian debian ffmpeg 13y ago The ff_h264_decode_sei function in libavcodec/h264_sei.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Supplemental enhancement information (SEI) data, which…
CVE-2011-3944 medium 6.8 FIX debian debian ffmpeg 13y ago The smacker_decode_header_tree function in libavcodec/smacker.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Smacker data.
CVE-2011-3941 high 7.5 FIX debian debian ffmpeg 13y ago The decode_mb function in libavcodec/error_resilience.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via vectors related to an uninitialized block index, which triggers…
CVE-2011-3935 medium 6.8 FIX debian debian ffmpeg 13y ago The codec_get_buffer function in ffmpeg.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via vectors related to a crafted image size.
CVE-2011-3934 medium 6.8 FIX debian debian ffmpeg 13y ago Double free vulnerability in the vp3_update_thread_context function in libavcodec/vp3.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted vp3 data.
CVE-2013-0859 critical 9.3 FIX debian debian ffmpeg 13y ago The add_doubles_metadata function in libavcodec/tiff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a negative or zero count value in a TIFF image, which triggers an…
CVE-2013-0858 critical 9.3 FIX debian debian ffmpeg 13y ago The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer tha…
CVE-2013-0857 critical 9.3 FIX debian debian ffmpeg 13y ago The decode_frame_ilbm function in libavcodec/iff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted height value in IFF PBM/ILBM bitmap data.
CVE-2013-0856 critical 9.3 FIX debian debian ffmpeg 13y ago The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nb_s…
CVE-2013-0855 critical 9.3 FIX debian debian ffmpeg 13y ago Integer overflow in the alac_decode_close function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a large number of samples per frame in Apple Los…
CVE-2013-0854 critical 9.3 FIX debian debian ffmpeg 13y ago The mjpeg_decode_scan_progressive_ac function in libavcodec/mjpegdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted MJPEG data.
CVE-2013-0853 critical 9.3 FIX debian debian ffmpeg 13y ago The wavpack_decode_frame function in libavcodec/wavpack.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted WavPack data, which triggers an out-of-bounds array ac…
CVE-2013-0852 critical 9.3 FIX debian debian ffmpeg 13y ago The parse_picture_segment function in libavcodec/pgssubdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted RLE data, which triggers an out-of-bounds array acc…
CVE-2013-0851 critical 9.3 FIX debian debian ffmpeg 13y ago The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which triggers an out-of-boun…
CVE-2013-0850 critical 9.3 FIX debian debian ffmpeg 13y ago The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted H.264 data, which triggers an out-of-bounds array access.
CVE-2013-0849 critical 9.3 FIX debian debian ffmpeg 13y ago The roq_decode_init function in libavcodec/roqvideodec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted (1) width or (2) height dimension that is not a multi…
CVE-2013-0848 critical 9.3 FIX debian debian ffmpeg 13y ago The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted width in huffyuv data with the predictor set to median and th…
CVE-2013-0847 critical 9.3 FIX debian debian ffmpeg 13y ago The ff_id3v2_parse function in libavformat/id3v2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via ID3v2 header data, which triggers an out-of-bounds array access.
CVE-2013-0846 critical 9.3 FIX debian debian ffmpeg 13y ago Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted QDM2 data, which triggers an out-…
CVE-2013-0845 critical 9.3 FIX debian debian ffmpeg 13y ago libavcodec/alsdec.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via a crafted block length, which triggers an out-of-bounds write.
CVE-2013-0844 critical 9.3 FIX debian debian ffmpeg 13y ago Off-by-one error in the adpcm_decode_frame function in libavcodec/adpcm.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via crafted DK4 data, which triggers an out-of-b…
CVE-2013-0869 critical 9.3 FIX debian debian ffmpeg 13y ago The field_end function in libavcodec/h264.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted H.264 data, related to an SPS and slice mismatch and an out-of-bou…
CVE-2013-0868 critical 9.3 FIX debian debian ffmpeg 13y ago libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted Huffyuv data, related to an out-of-bounds write and (1) unchecked return codes from th…
CVE-2013-0867 critical 9.3 FIX debian debian ffmpeg 13y ago The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remote attackers to have unspecified impact via crafte…
CVE-2013-0866 critical 9.3 FIX debian debian ffmpeg 13y ago The aac_decode_init function in libavcodec/aacdec.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large number of channels in an AAC file, …
CVE-2013-0865 critical 9.3 FIX debian debian ffmpeg 13y ago The vqa_decode_chunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large (1) cbp0 or (2) cbpz chunk in We…
CVE-2013-0864 critical 10.0 FIX debian debian ffmpeg 13y ago The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before 1.1.2 performs an incorrect calculation for an "end pointer," which allows remote attackers to have an unspecified impact via cr…
CVE-2013-0863 critical 9.3 FIX debian debian ffmpeg 13y ago Buffer overflow in the rle_decode function in libavcodec/sanm.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via crafted LucasArts Smush video d…
CVE-2013-0862 critical 9.3 FIX debian debian ffmpeg 13y ago Multiple integer overflows in the process_frame_obj function in libavcodec/sanm.c in FFmpeg before 1.1.2 allow remote attackers to have an unspecified impact via crafted image dimensions in LucasArts…
CVE-2013-0861 medium 5.0 FIX debian debian ffmpeg 13y ago The avcodec_decode_audio4 function in libavcodec/utils.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 allows remote attackers to trigger memory corruption via vectors related to the channel layout.
CVE-2013-0860 medium 4.3 FIX debian debian ffmpeg 13y ago The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers t…
CVE-2013-4265 critical 10.0 FIX debian debian ffmpeg 13y ago The av_reallocp_array function in libavutil/mem.c in FFmpeg before 2.0.1 has an unspecified impact and remote vectors related to a "wrong return code" and a resultant NULL pointer dereference.
CVE-2013-4264 medium 4.3 FIX debian debian ffmpeg 13y ago The kempf_decode_tile function in libavcodec/g2meet.c in FFmpeg before 2.0.1 allows remote attackers to cause a denial of service (out-of-bounds heap write) via a G2M4 encoded file.
CVE-2013-4263 high 7.5 FIX debian debian ffmpeg 13y ago libavfilter in FFmpeg before 2.0.1 has unspecified impact and remote vectors related to a crafted "plane," which triggers an out-of-bounds heap write.
CVE-2013-0878 critical 9.3 FIX debian debian ffmpeg 13y ago The advance_line function in libavcodec/targa.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted Targa image data, related to an out-of-bounds array access.
CVE-2013-0877 critical 9.3 FIX debian debian ffmpeg 13y ago The old_codec37 function in libavcodec/sanm.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted LucasArts Smush data that has a large size when decoded, related…
CVE-2013-0876 critical 9.3 FIX debian debian ffmpeg 13y ago Multiple integer overflows in the (1) old_codec37 and (2) old_codec47 functions in libavcodec/sanm.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via crafted LucasArts …
CVE-2013-0875 critical 9.3 FIX debian debian ffmpeg 13y ago The ff_add_png_paeth_prediction function in libavcodec/pngdec.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via a crafted PNG image, related to an out-of-bounds array…
CVE-2013-0874 critical 9.3 FIX debian debian ffmpeg 13y ago The (1) doubles2str and (2) shorts2str functions in libavcodec/tiff.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via a crafted TIFF image, related to an out-of-bounds…
CVE-2013-0873 critical 10.0 FIX debian debian ffmpeg 13y ago The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel count, related to "freeing invalid addresses."
CVE-2013-0872 critical 10.0 FIX debian debian ffmpeg 13y ago The swr_init function in libswresample/swresample.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid or unsupported (1) input or (2) output channel layout, …
CVE-2013-3675 medium 4.3 FIX debian debian ffmpeg 13y ago The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, …
CVE-2013-3674 medium 4.3 FIX debian debian ffmpeg 13y ago The cdg_decode_frame function in cdgraphics.c in libavcodec in FFmpeg before 1.2.1 does not validate the presence of non-header data in a buffer, which allows remote attackers to cause a denial of se…
CVE-2013-3673 medium 4.3 FIX debian debian ffmpeg 13y ago The gif_decode_frame function in gifdec.c in libavcodec in FFmpeg before 1.2.1 does not properly manage the disposal methods of frames, which allows remote attackers to cause a denial of service (out…
CVE-2013-3672 medium 4.3 FIX debian debian ffmpeg 13y ago The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before 1.2.1 does not validate the relationship between a horizontal coordinate and a width value, which allows remote attackers to c…
CVE-2013-3671 medium 4.3 FIX debian debian ffmpeg 13y ago The format_line function in log.c in libavutil in FFmpeg before 1.2.1 uses inapplicable offset data during a certain category calculation, which allows remote attackers to cause a denial of service (…
CVE-2013-3670 medium 4.3 FIX debian debian ffmpeg 13y ago The rle_unpack function in vmdav.c in libavcodec in FFmpeg git 20130328 through 20130501 does not properly use the bytestream2 API, which allows remote attackers to cause a denial of service (out-of-…
CVE-2013-2496 high 7.5 FIX debian debian ffmpeg 13y ago The msrle_decode_8_16_24_32 function in msrledec.c in libavcodec in FFmpeg through 1.1.3 does not properly determine certain end pointers, which allows remote attackers to cause a denial of service (…
CVE-2013-2495 high 7.5 FIX debian debian ffmpeg 13y ago The iff_read_header function in iff.c in libavformat in FFmpeg through 1.1.3 does not properly handle data sizes for Interchange File Format (IFF) data during operations involving a CMAP chunk or a v…
CVE-2013-2277 high 7.5 FIX debian debian ffmpeg 14y ago The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 1.1.3 does not validate the relationship between luma depth and chroma depth, which allows remote attackers t…
CVE-2013-2276 high 7.5 FIX debian debian ffmpeg 14y ago The avcodec_decode_audio4 function in utils.c in libavcodec in FFmpeg before 1.1.3 does not verify the decoding state before proceeding with certain skip operations, which allows remote attackers to …
CVE-2013-0894 high 7.5 FIX debian debian linux-kernelsuse suse googleffmpeg 14y ago Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and L…
CVE-2011-3937 critical 10.0 FIX debian debian ffmpeglibav 14y ago The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.…
CVE-2012-2804 critical 10.0 FIX debian debian libavffmpeg 14y ago Unspecified vulnerability in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors, related to "reallocation code" and the luma height and width.
CVE-2012-2803 critical 10.0 FIX debian debian libavffmpeg 14y ago Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, r…
CVE-2012-2802 critical 10.0 FIX debian debian libavffmpeg 14y ago Unspecified vulnerability in the ac3_decode_frame function in libavcodec/ac3dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to the "number of o…
CVE-2012-2801 critical 10.0 FIX debian debian libavffmpeg 14y ago Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to dimensions and "out of arra…
CVE-2012-2800 critical 10.0 libavffmpeg 14y ago Unspecified vulnerability in the ff_ivi_process_empty_tile function in libavcodec/ivi_common.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attac…
CVE-2012-2799 critical 10.0 FIX debian debian ffmpeg 14y ago Unspecified vulnerability in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to the "put bit buffer when num_saved_bits is reset."