Search

Found 205 results in 18ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-9608 medium 6.5 6.5 FIX debian debian ffmpeg 9y ago The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.
CVE-2017-17555 medium 6.5 6.5 FIX debian debian aubioffmpeg 9y ago The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of servi…
CVE-2017-17081 medium 6.5 6.5 FIX debian debian ffmpeg 9y ago The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does not properly validate widths and heights, which allows remote attackers to cause a denial of service (integer signedne…
CVE-2017-16840 critical 9.8 9.8 FIX arch archdebian debian ffmpeg 9y ago The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related t…
CVE-2017-15186 medium 6.5 6.5 FIX debian debian ffmpeg 9y ago Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
CVE-2017-14223 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, which claims a large …
CVE-2017-14222 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which claims a large "item_c…
CVE-2017-14171 medium 6.5 6.5 FIX slesarch archdebian debian ffmpeg 9y ago In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted NSV file, which claims a l…
CVE-2017-14170 medium 6.5 6.5 FIX slesarch archdebian debian ffmpeg 9y ago In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims…
CVE-2017-14059 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. When a crafted CINE file, which claims a large "duration" field in the header but…
CVE-2017-14058 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote attackers to cause a denial of service (infinite l…
CVE-2017-14057 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" …
CVE-2017-14056 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted RL2 file, which claims a large "…
CVE-2017-14055 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large "…
CVE-2017-14054 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted IVR file, which claims a large "len" fiel…
CVE-2013-0870 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.
CVE-2012-2781 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2780.
CVE-2012-2780 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2781.
CVE-2012-2778 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2780, and CVE-2012-2781.
CVE-2012-2773 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2781.
CVE-2012-2771 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2773, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2781.
CVE-2017-7866 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c.
CVE-2017-7865 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align…
CVE-2017-7863 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.
CVE-2017-7862 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c.
CVE-2017-7859 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.
CVE-2016-10192 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failur…
CVE-2016-10191 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by levera…
CVE-2016-10190 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a nega…
CVE-2016-6164 critical 9.8 9.8 FIX debian debian ffmpeg 10y ago Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors …
CVE-2016-9561 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a cr…
CVE-2016-8595 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
CVE-2016-7905 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file.
CVE-2016-7785 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
CVE-2016-7562 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.
CVE-2016-7555 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.
CVE-2016-7122 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure.
CVE-2016-6881 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file.
CVE-2016-2839 medium 6.5 6.5 FIX slesdebian debian linux-kernel ffmpegmozilla 10y ago Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with libav header allocation in FFmpeg 0.10, which allo…
CVE-2016-2213 medium 6.5 6.5 FIX debian debian ffmpeg 11y ago The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a denial of service (out-of-bounds array read access) via crafted JPEG 2000 data.
CVE-2016-1898 medium 5.5 5.5 FIX debian debianubuntu ubuntususe suse ffmpeg 11y ago FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP reques…
CVE-2016-1897 medium 5.5 5.5 FIX debian debianubuntu ubuntususe suse ffmpeg 11y ago FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request…
CVE-2015-8365 medium 6.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels…
CVE-2015-8364 medium 6.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-o…
CVE-2015-8363 medium 6.8 FIX debian debian ffmpeg 11y ago The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not enforce uniqueness of the SIZ marker in a JPEG 2000 im…
CVE-2015-8218 medium 6.8 FIX debian debian ffmpeg 11y ago The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array a…
CVE-2015-6761 medium 6.8 FIX debian debian ffmpeggoogle 11y ago The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as used in Google Chrome before 46.0.2490.71 and other products, relies on a coefficient-partition count during multi-threa…
CVE-2015-1872 medium 6.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of components in a JPEG-LS Start Of Frame segment, which allows remote attackers to cause…
CVE-2015-3395 medium 6.8 FIX debian debianubuntu ubuntu ffmpeglibav 11y ago The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 all…
CVE-2015-3417 medium 6.8 FIX debian debian ffmpeg 11y ago Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other im…
CVE-2014-9676 medium 6.8 FIX debian debian ffmpeg 11y ago The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memo…
CVE-2014-9319 medium 5.0 FIX debian debian ffmpeg 12y ago The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds acc…
CVE-2014-5272 medium 6.8 FIX debian debian ffmpeg 12y ago libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote attackers to have unspecified impact via a crafted iff image, which triggers an …
CVE-2014-2099 medium 6.8 FIX debian debian ffmpeg 12y ago The msrle_decode_frame function in libavcodec/msrle.c in FFmpeg before 2.1.4 does not properly calculate line sizes, which allows remote attackers to cause a denial of service (out-of-bounds array ac…
CVE-2014-2098 medium 6.8 FIX debian debian ffmpeg 12y ago libavcodec/wmalosslessdec.c in FFmpeg before 2.1.4 uses an incorrect data-structure size for certain coefficients, which allows remote attackers to cause a denial of service (memory corruption) or po…
CVE-2014-2097 medium 6.8 FIX debian debian ffmpeg 12y ago The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows remote attackers to cause a denial of service (out…
CVE-2014-2263 medium 6.8 FIX debian debian ffmpeg 12y ago The mpegts_write_pmt function in the MPEG2 transport stream (aka DVB) muxer (libavformat/mpegtsenc.c) in FFmpeg, possibly 2.1 and earlier, allows remote attackers to have unspecified impact and vecto…
CVE-2012-6618 low 2.6 FIX debian debian ffmpeg 13y ago The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a craft…
CVE-2012-6617 medium 4.3 FIX debian debian ffmpeg 13y ago The prepare_sdp_description function in ffserver.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (crash) via vectors related to the rtp format.
CVE-2012-6616 medium 5.0 FIX debian debian ffmpeg 13y ago The mov_text_decode_frame function in libavcodec/movtextdec.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via crafted 3GPP TS 26.245 dat…
CVE-2012-6615 medium 4.3 FIX debian debian ffmpeg 13y ago The ff_ass_split_override_codes function in libavcodec/ass_split.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a subtitle dial…
CVE-2013-4358 medium 5.0 FIX debian debian ffmpeg 13y ago libavcodec/h264.c in FFmpeg before 0.11.4 allows remote attackers to cause a denial of service (crash) via vectors related to alternating bit depths in H.264 data.
CVE-2013-7024 medium 6.8 FIX debian debian ffmpeg 13y ago The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not consider the component number in certain calculations, which allows remote attackers to cause a denial of s…
CVE-2013-7023 medium 6.8 FIX debian debian ffmpeg 13y ago The ff_combine_frame function in libavcodec/parser.c in FFmpeg before 2.1 does not properly handle certain memory-allocation errors, which allows remote attackers to cause a denial of service (out-of…
CVE-2013-7022 medium 6.8 FIX debian debian ffmpeg 13y ago The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 does not properly allocate memory for tiles, which allows remote attackers to cause a denial of service (out-of-bounds array …
CVE-2013-7021 medium 6.8 FIX debian debian ffmpeg 13y ago The filter_frame function in libavfilter/vf_fps.c in FFmpeg before 2.1 does not properly ensure the availability of FIFO content, which allows remote attackers to cause a denial of service (double fr…
CVE-2013-7020 medium 6.8 FIX debian debian ffmpeg 13y ago The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of servic…
CVE-2013-7019 medium 6.8 FIX debian debian ffmpeg 13y ago The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers to cause a denial of service (out-of-bounds array …
CVE-2013-7018 medium 6.8 FIX debian debian ffmpeg 13y ago libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the use of valid code-block dimension values, which allows remote attackers to cause a denial of service (out-of-bounds array access) or …
CVE-2013-7017 medium 6.8 FIX debian debian ffmpeg 13y ago libavcodec/jpeg2000.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via crafted JPEG2000 data.
CVE-2013-7016 medium 6.8 FIX debian debian ffmpeg 13y ago The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the expected sample separation, which allows remote attackers to cause a denial of service (out-of-bounds array a…
CVE-2013-7015 medium 6.8 FIX debian debian ffmpeg 13y ago The flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before 2.1 does not properly validate a certain height value, which allows remote attackers to cause a denial of service (out-of-bo…
CVE-2013-7014 medium 6.8 FIX debian debian ffmpeg 13y ago Integer signedness error in the add_bytes_l2_c function in libavcodec/pngdsp.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have …
CVE-2013-7013 medium 6.8 FIX debian debian ffmpeg 13y ago The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote attackers to cause a denial of service (out-of-bound…
CVE-2013-7012 medium 6.8 FIX debian debian ffmpeg 13y ago The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not prevent attempts to use non-zero image offsets, which allows remote attackers to cause a denial of service (out-of-bound…
CVE-2013-7011 medium 6.8 FIX debian debian ffmpeg 13y ago The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not prevent changes to global parameters, which allows remote attackers to cause a denial of service (out-of-bounds array ac…
CVE-2013-7010 medium 6.8 FIX debian debian ffmpeg 13y ago Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other imp…
CVE-2013-7009 medium 6.8 FIX debian debian ffmpeg 13y ago The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows remote attackers to cause a denial of service (out-of-bounds…
CVE-2013-7008 medium 6.8 FIX debian debian ffmpeg 13y ago The decode_slice_header function in libavcodec/h264.c in FFmpeg before 2.1 incorrectly relies on a certain droppable field, which allows remote attackers to cause a denial of service (deadlock) or po…
CVE-2011-3950 medium 6.8 FIX debian debian ffmpeg 13y ago The dirac_decode_data_unit function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via a crafted value in the reference pictures number.
CVE-2011-3949 medium 6.8 FIX debian debian ffmpeg 13y ago The dirac_unpack_idwt_params function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Dirac data.
CVE-2011-3946 medium 6.8 FIX debian debian ffmpeg 13y ago The ff_h264_decode_sei function in libavcodec/h264_sei.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Supplemental enhancement information (SEI) data, which…
CVE-2011-3944 medium 6.8 FIX debian debian ffmpeg 13y ago The smacker_decode_header_tree function in libavcodec/smacker.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Smacker data.
CVE-2011-3935 medium 6.8 FIX debian debian ffmpeg 13y ago The codec_get_buffer function in ffmpeg.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via vectors related to a crafted image size.
CVE-2011-3934 medium 6.8 FIX debian debian ffmpeg 13y ago Double free vulnerability in the vp3_update_thread_context function in libavcodec/vp3.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted vp3 data.
CVE-2013-0859 critical 9.3 FIX debian debian ffmpeg 13y ago The add_doubles_metadata function in libavcodec/tiff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a negative or zero count value in a TIFF image, which triggers an…
CVE-2013-0858 critical 9.3 FIX debian debian ffmpeg 13y ago The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer tha…
CVE-2013-0857 critical 9.3 FIX debian debian ffmpeg 13y ago The decode_frame_ilbm function in libavcodec/iff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted height value in IFF PBM/ILBM bitmap data.
CVE-2013-0856 critical 9.3 FIX debian debian ffmpeg 13y ago The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nb_s…
CVE-2013-0855 critical 9.3 FIX debian debian ffmpeg 13y ago Integer overflow in the alac_decode_close function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a large number of samples per frame in Apple Los…
CVE-2013-0854 critical 9.3 FIX debian debian ffmpeg 13y ago The mjpeg_decode_scan_progressive_ac function in libavcodec/mjpegdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted MJPEG data.
CVE-2013-0853 critical 9.3 FIX debian debian ffmpeg 13y ago The wavpack_decode_frame function in libavcodec/wavpack.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted WavPack data, which triggers an out-of-bounds array ac…
CVE-2013-0852 critical 9.3 FIX debian debian ffmpeg 13y ago The parse_picture_segment function in libavcodec/pgssubdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted RLE data, which triggers an out-of-bounds array acc…
CVE-2013-0851 critical 9.3 FIX debian debian ffmpeg 13y ago The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which triggers an out-of-boun…
CVE-2013-0850 critical 9.3 FIX debian debian ffmpeg 13y ago The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted H.264 data, which triggers an out-of-bounds array access.
CVE-2013-0849 critical 9.3 FIX debian debian ffmpeg 13y ago The roq_decode_init function in libavcodec/roqvideodec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted (1) width or (2) height dimension that is not a multi…
CVE-2013-0848 critical 9.3 FIX debian debian ffmpeg 13y ago The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted width in huffyuv data with the predictor set to median and th…
CVE-2013-0847 critical 9.3 FIX debian debian ffmpeg 13y ago The ff_id3v2_parse function in libavformat/id3v2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via ID3v2 header data, which triggers an out-of-bounds array access.
CVE-2013-0846 critical 9.3 FIX debian debian ffmpeg 13y ago Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted QDM2 data, which triggers an out-…
CVE-2013-0845 critical 9.3 FIX debian debian ffmpeg 13y ago libavcodec/alsdec.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via a crafted block length, which triggers an out-of-bounds write.