Search

Found 119 results in 72ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-9608 medium 6.5 6.5 FIX debian debian ffmpeg 9y ago The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.
CVE-2017-17555 medium 6.5 6.5 FIX debian debian aubioffmpeg 9y ago The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of servi…
CVE-2017-17081 medium 6.5 6.5 FIX debian debian ffmpeg 9y ago The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does not properly validate widths and heights, which allows remote attackers to cause a denial of service (integer signedne…
CVE-2017-15186 medium 6.5 6.5 FIX debian debian ffmpeg 9y ago Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
CVE-2017-14223 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, which claims a large …
CVE-2017-14222 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which claims a large "item_c…
CVE-2017-14171 medium 6.5 6.5 FIX slesarch archdebian debian ffmpeg 9y ago In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted NSV file, which claims a l…
CVE-2017-14170 medium 6.5 6.5 FIX slesarch archdebian debian ffmpeg 9y ago In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims…
CVE-2017-14059 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. When a crafted CINE file, which claims a large "duration" field in the header but…
CVE-2017-14058 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote attackers to cause a denial of service (infinite l…
CVE-2017-14057 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" …
CVE-2017-14056 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted RL2 file, which claims a large "…
CVE-2017-14055 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large "…
CVE-2017-14054 medium 6.5 6.5 FIX arch archdebian debian ffmpeg 9y ago In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted IVR file, which claims a large "len" fiel…
CVE-2016-9561 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a cr…
CVE-2016-8595 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
CVE-2016-7905 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file.
CVE-2016-7785 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
CVE-2016-7562 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.
CVE-2016-7555 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.
CVE-2016-7122 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure.
CVE-2016-6881 medium 5.5 5.5 FIX debian debian ffmpeg 10y ago The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file.
CVE-2016-2839 medium 6.5 6.5 FIX slesdebian debian linux-kernel ffmpegmozilla 10y ago Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with libav header allocation in FFmpeg 0.10, which allo…
CVE-2016-2213 medium 6.5 6.5 FIX debian debian ffmpeg 11y ago The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a denial of service (out-of-bounds array read access) via crafted JPEG 2000 data.
CVE-2016-1898 medium 5.5 5.5 FIX debian debianubuntu ubuntususe suse ffmpeg 11y ago FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP reques…
CVE-2016-1897 medium 5.5 5.5 FIX debian debianubuntu ubuntususe suse ffmpeg 11y ago FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request…
CVE-2015-8365 medium 6.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels…
CVE-2015-8364 medium 6.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-o…
CVE-2015-8363 medium 6.8 FIX debian debian ffmpeg 11y ago The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not enforce uniqueness of the SIZ marker in a JPEG 2000 im…
CVE-2015-8218 medium 6.8 FIX debian debian ffmpeg 11y ago The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array a…
CVE-2015-6761 medium 6.8 FIX debian debian ffmpeggoogle 11y ago The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as used in Google Chrome before 46.0.2490.71 and other products, relies on a coefficient-partition count during multi-threa…
CVE-2015-1872 medium 6.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of components in a JPEG-LS Start Of Frame segment, which allows remote attackers to cause…
CVE-2015-3395 medium 6.8 FIX debian debianubuntu ubuntu ffmpeglibav 11y ago The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 all…
CVE-2015-3417 medium 6.8 FIX debian debian ffmpeg 11y ago Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other im…
CVE-2014-9676 medium 6.8 FIX debian debian ffmpeg 11y ago The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memo…
CVE-2014-9319 medium 5.0 FIX debian debian ffmpeg 12y ago The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds acc…
CVE-2014-5272 medium 6.8 FIX debian debian ffmpeg 12y ago libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote attackers to have unspecified impact via a crafted iff image, which triggers an …
CVE-2014-2099 medium 6.8 FIX debian debian ffmpeg 12y ago The msrle_decode_frame function in libavcodec/msrle.c in FFmpeg before 2.1.4 does not properly calculate line sizes, which allows remote attackers to cause a denial of service (out-of-bounds array ac…
CVE-2014-2098 medium 6.8 FIX debian debian ffmpeg 12y ago libavcodec/wmalosslessdec.c in FFmpeg before 2.1.4 uses an incorrect data-structure size for certain coefficients, which allows remote attackers to cause a denial of service (memory corruption) or po…
CVE-2014-2097 medium 6.8 FIX debian debian ffmpeg 12y ago The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows remote attackers to cause a denial of service (out…
CVE-2014-2263 medium 6.8 FIX debian debian ffmpeg 12y ago The mpegts_write_pmt function in the MPEG2 transport stream (aka DVB) muxer (libavformat/mpegtsenc.c) in FFmpeg, possibly 2.1 and earlier, allows remote attackers to have unspecified impact and vecto…
CVE-2012-6618 low 2.6 FIX debian debian ffmpeg 13y ago The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a craft…
CVE-2012-6617 medium 4.3 FIX debian debian ffmpeg 13y ago The prepare_sdp_description function in ffserver.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (crash) via vectors related to the rtp format.
CVE-2012-6616 medium 5.0 FIX debian debian ffmpeg 13y ago The mov_text_decode_frame function in libavcodec/movtextdec.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via crafted 3GPP TS 26.245 dat…
CVE-2012-6615 medium 4.3 FIX debian debian ffmpeg 13y ago The ff_ass_split_override_codes function in libavcodec/ass_split.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a subtitle dial…
CVE-2013-4358 medium 5.0 FIX debian debian ffmpeg 13y ago libavcodec/h264.c in FFmpeg before 0.11.4 allows remote attackers to cause a denial of service (crash) via vectors related to alternating bit depths in H.264 data.
CVE-2013-7024 medium 6.8 FIX debian debian ffmpeg 13y ago The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not consider the component number in certain calculations, which allows remote attackers to cause a denial of s…
CVE-2013-7023 medium 6.8 FIX debian debian ffmpeg 13y ago The ff_combine_frame function in libavcodec/parser.c in FFmpeg before 2.1 does not properly handle certain memory-allocation errors, which allows remote attackers to cause a denial of service (out-of…
CVE-2013-7022 medium 6.8 FIX debian debian ffmpeg 13y ago The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 does not properly allocate memory for tiles, which allows remote attackers to cause a denial of service (out-of-bounds array …
CVE-2013-7021 medium 6.8 FIX debian debian ffmpeg 13y ago The filter_frame function in libavfilter/vf_fps.c in FFmpeg before 2.1 does not properly ensure the availability of FIFO content, which allows remote attackers to cause a denial of service (double fr…
CVE-2013-7020 medium 6.8 FIX debian debian ffmpeg 13y ago The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of servic…
CVE-2013-7019 medium 6.8 FIX debian debian ffmpeg 13y ago The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers to cause a denial of service (out-of-bounds array …
CVE-2013-7018 medium 6.8 FIX debian debian ffmpeg 13y ago libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the use of valid code-block dimension values, which allows remote attackers to cause a denial of service (out-of-bounds array access) or …
CVE-2013-7017 medium 6.8 FIX debian debian ffmpeg 13y ago libavcodec/jpeg2000.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via crafted JPEG2000 data.
CVE-2013-7016 medium 6.8 FIX debian debian ffmpeg 13y ago The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the expected sample separation, which allows remote attackers to cause a denial of service (out-of-bounds array a…
CVE-2013-7015 medium 6.8 FIX debian debian ffmpeg 13y ago The flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before 2.1 does not properly validate a certain height value, which allows remote attackers to cause a denial of service (out-of-bo…
CVE-2013-7014 medium 6.8 FIX debian debian ffmpeg 13y ago Integer signedness error in the add_bytes_l2_c function in libavcodec/pngdsp.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have …
CVE-2013-7013 medium 6.8 FIX debian debian ffmpeg 13y ago The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote attackers to cause a denial of service (out-of-bound…
CVE-2013-7012 medium 6.8 FIX debian debian ffmpeg 13y ago The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not prevent attempts to use non-zero image offsets, which allows remote attackers to cause a denial of service (out-of-bound…
CVE-2013-7011 medium 6.8 FIX debian debian ffmpeg 13y ago The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not prevent changes to global parameters, which allows remote attackers to cause a denial of service (out-of-bounds array ac…
CVE-2013-7010 medium 6.8 FIX debian debian ffmpeg 13y ago Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other imp…
CVE-2013-7009 medium 6.8 FIX debian debian ffmpeg 13y ago The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows remote attackers to cause a denial of service (out-of-bounds…
CVE-2013-7008 medium 6.8 FIX debian debian ffmpeg 13y ago The decode_slice_header function in libavcodec/h264.c in FFmpeg before 2.1 incorrectly relies on a certain droppable field, which allows remote attackers to cause a denial of service (deadlock) or po…
CVE-2011-3950 medium 6.8 FIX debian debian ffmpeg 13y ago The dirac_decode_data_unit function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via a crafted value in the reference pictures number.
CVE-2011-3949 medium 6.8 FIX debian debian ffmpeg 13y ago The dirac_unpack_idwt_params function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Dirac data.
CVE-2011-3946 medium 6.8 FIX debian debian ffmpeg 13y ago The ff_h264_decode_sei function in libavcodec/h264_sei.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Supplemental enhancement information (SEI) data, which…
CVE-2011-3944 medium 6.8 FIX debian debian ffmpeg 13y ago The smacker_decode_header_tree function in libavcodec/smacker.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Smacker data.
CVE-2011-3935 medium 6.8 FIX debian debian ffmpeg 13y ago The codec_get_buffer function in ffmpeg.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via vectors related to a crafted image size.
CVE-2011-3934 medium 6.8 FIX debian debian ffmpeg 13y ago Double free vulnerability in the vp3_update_thread_context function in libavcodec/vp3.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted vp3 data.
CVE-2013-0861 medium 5.0 FIX debian debian ffmpeg 13y ago The avcodec_decode_audio4 function in libavcodec/utils.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 allows remote attackers to trigger memory corruption via vectors related to the channel layout.
CVE-2013-0860 medium 4.3 FIX debian debian ffmpeg 13y ago The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers t…
CVE-2013-4264 medium 4.3 FIX debian debian ffmpeg 13y ago The kempf_decode_tile function in libavcodec/g2meet.c in FFmpeg before 2.0.1 allows remote attackers to cause a denial of service (out-of-bounds heap write) via a G2M4 encoded file.
CVE-2013-3675 medium 4.3 FIX debian debian ffmpeg 13y ago The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, …
CVE-2013-3674 medium 4.3 FIX debian debian ffmpeg 13y ago The cdg_decode_frame function in cdgraphics.c in libavcodec in FFmpeg before 1.2.1 does not validate the presence of non-header data in a buffer, which allows remote attackers to cause a denial of se…
CVE-2013-3673 medium 4.3 FIX debian debian ffmpeg 13y ago The gif_decode_frame function in gifdec.c in libavcodec in FFmpeg before 1.2.1 does not properly manage the disposal methods of frames, which allows remote attackers to cause a denial of service (out…
CVE-2013-3672 medium 4.3 FIX debian debian ffmpeg 13y ago The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before 1.2.1 does not validate the relationship between a horizontal coordinate and a width value, which allows remote attackers to c…
CVE-2013-3671 medium 4.3 FIX debian debian ffmpeg 13y ago The format_line function in log.c in libavutil in FFmpeg before 1.2.1 uses inapplicable offset data during a certain category calculation, which allows remote attackers to cause a denial of service (…
CVE-2013-3670 medium 4.3 FIX debian debian ffmpeg 13y ago The rle_unpack function in vmdav.c in libavcodec in FFmpeg git 20130328 through 20130501 does not properly use the bytestream2 API, which allows remote attackers to cause a denial of service (out-of-…
CVE-2012-2774 medium 5.0 FIX debian debian ffmpeg 14y ago The ff_MPV_frame_start function in libavcodec/mpegvideo.c in FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) via unspecified vectors, related to starting "…
CVE-2012-0855 medium 5.0 FIX debian debian ffmpeg 14y ago Heap-based buffer overflow in the get_sot function in the J2K decoder (j2k.c) in libavcodec in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) via unspeci…
CVE-2012-0849 medium 4.3 FIX debian debian ffmpeg 14y ago Integer overflow in the ff_j2k_dwt_init function in libavcodec/j2k_dwt.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a c…
CVE-2011-4579 medium 4.3 FIX debian debian ffmpeglibav 14y ago The svq1_decode_frame function in the SVQ1 decoder (svq1dec.c) in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.…
CVE-2011-4364 medium 6.8 FIX debian debian ffmpeglibav 14y ago Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9 and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.…
CVE-2011-4353 medium 4.3 FIX debian debian ffmpeglibav 14y ago The (1) av_image_fill_pointers, (2) vp5_parse_coeff, and (3) vp6_parse_coeff functions in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x…
CVE-2011-4352 medium 6.8 FIX debian debian libavffmpeg 14y ago Integer overflow in the vp3_dequant function in the VP3 decoder (vp3.c) in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x …
CVE-2011-3945 medium 6.8 FIX debian debian ffmpeglibav 14y ago The decode_frame function in the KVG1 decoder (kgv1dec.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5,…
CVE-2012-0857 medium 5.0 FIX debian debian ffmpeg 14y ago Multiple buffer overflows in the get_qcx function in the J2K decoder (j2kdec.c) in libavcode in FFmpeg before 0.9.1 allow remote attackers to cause a denial of service (application crash) via unspeci…
CVE-2012-0856 low 2.6 FIX debian debian ffmpeg 14y ago Heap-based buffer overflow in the MPV_frame_start function in libavcodec/mpegvideo.c in FFmpeg before 0.9.1, when the lowres option is enabled, allows remote attackers to cause a denial of service (a…
CVE-2012-0854 medium 5.0 FIX debian debian ffmpeg 14y ago The dpcm_decode_frame function in libavcodec/dpcm.c in FFmpeg before 0.9.1 does not use the proper pointer after an audio API change, which allows remote attackers to cause a denial of service (appli…
CVE-2012-0850 medium 4.3 FIX debian debian ffmpeg 14y ago The sbr_qmf_synthesis function in libavcodec/aacsbr.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) via a crafted mpg file that triggers memory corru…
CVE-2012-0848 medium 4.3 FIX debian debian ffmpeg 14y ago Heap-based buffer overflow in the ws_snd_decode_frame function in libavcodec/ws-snd1.c in FFmpeg 0.9.1 allows remote attackers to cause a denial of service (application crash) via a crafted media fil…
CVE-2012-0847 medium 4.3 FIX debian debian ffmpeg 14y ago Heap-based buffer overflow in the avfilter_filter_samples function in libavfilter/avfilter.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) via a craf…
CVE-2012-0859 medium 6.8 FIX debian debian ffmpeg 14y ago The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary co…
CVE-2012-0858 medium 6.8 FIX debian debian ffmpeglibav 14y ago The Shorten codec (shorten.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, all…
CVE-2012-0853 medium 6.8 FIX debian debian ffmpeglibav 14y ago The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec in FFmpeg 0.7.x before 0.7.12, and 0.8.x before 0.8.11; and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x bef…
CVE-2012-0852 medium 6.8 FIX debian debian ffmpeglibav 14y ago The adpcm_decode_frame function in adpcm.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers…
CVE-2012-0851 medium 6.8 FIX debian debian ffmpeglibav 14y ago The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows …
CVE-2011-3952 medium 6.8 FIX debian debian ffmpeglibav 14y ago The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause…
CVE-2011-3951 medium 6.8 FIX debian debian libavffmpeg 14y ago The dpcm_decode_frame function in dpcm.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to…
CVE-2011-3947 medium 6.8 FIX debian debian ffmpeglibav 14y ago Buffer overflow in mjpegbdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, al…