Skip to main content

Vendor archive

ffmpeg CVEs

Beta · best-effort

482 CVEs tagged to vendor ffmpeg105 Critical, 147 High, 225 Medium, 5 Low, 0 Unrated.

CVE-2012-2773

Published Aug 9, 2017

Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-2771

Published Aug 9, 2017

Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2773, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11719

Published Jul 28, 2017

The dnxhd_decode_header function in libavcodec/dnxhddec.c in FFmpeg 3.0 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have u…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11665

Published Jul 27, 2017

The ff_amf_get_field_value function in libavformat/rtmppkt.c in FFmpeg 3.3.2 allows remote RTMP servers to cause a denial of service (Segmentation Violation and application crash)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11399

Published Jul 17, 2017

Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg 2.4 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access and…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9996

Published Jun 28, 2017

The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not excl…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9995

Published Jun 28, 2017

libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of service (heap-based buffer overfl…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9994

Published Jun 28, 2017

libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows rem…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9993

Published Jun 28, 2017

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9992

Published Jun 28, 2017

Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9991

Published Jun 28, 2017

Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x b…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9990

Published Jun 28, 2017

Stack-based buffer overflow in the color_string_to_rgba function in libavcodec/xpmdec.c in FFmpeg 3.3 before 3.3.1 allows remote attackers to cause a denial of service (applicatio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7866

Published Apr 14, 2017

FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7865

Published Apr 14, 2017

FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7863

Published Apr 14, 2017

FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7862

Published Apr 14, 2017

FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7859

Published Apr 14, 2017

FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5361

Published Mar 20, 2017

Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10192

Published Feb 9, 2017

Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10191

Published Feb 9, 2017

Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10190

Published Feb 9, 2017

Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6920

Published Jan 23, 2017

Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of service (application crash) via vec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6164

Published Jan 23, 2017

Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9561

Published Dec 23, 2016

The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8595

Published Dec 23, 2016

The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 482 CVEsPage 10 of 20