Skip to main content

Vendor archive

ffmpeg CVEs

Beta · best-effort

482 CVEs tagged to vendor ffmpeg105 Critical, 147 High, 225 Medium, 5 Low, 0 Unrated.

CVE-2017-9608

Published Dec 27, 2017

The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17081

Published Nov 30, 2017

The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does not properly validate widths and heights, which allows remote attackers to cause a denial of servi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16840

Published Nov 21, 2017

The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15672

Published Nov 6, 2017

The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via a crafted MP4 file, which trig…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15186

Published Oct 24, 2017

Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14767

Published Sep 27, 2017

The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allows remote attackers to cause a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14225

Published Sep 9, 2017

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14223

Published Sep 9, 2017

In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14222

Published Sep 9, 2017

In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which cl…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14171

Published Sep 7, 2017

In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted NSV fi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14170

Published Sep 7, 2017

In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MX…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14169

Published Sep 7, 2017

In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" f…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14059

Published Aug 31, 2017

In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. When a crafted CINE file, which claims a large "duration" fie…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14058

Published Aug 31, 2017

In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote attackers to cause a denial of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14057

Published Aug 31, 2017

In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "n…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14056

Published Aug 31, 2017

In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted RL2 file, wh…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14055

Published Aug 31, 2017

In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, wh…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14054

Published Aug 31, 2017

In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted IVR file, which claim…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0870

Published Aug 28, 2017

The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-2805

Published Aug 28, 2017

Unspecified vulnerability in FFMPEG 0.10 allows remote attackers to cause a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2781

Published Aug 9, 2017

Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-2780

Published Aug 9, 2017

Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-2778

Published Aug 9, 2017

Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2780, and CVE-2012-2…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 201-225 of 482 CVEsPage 9 of 20