Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ffmpeg HIGH 8.8
CVE-2018-1999011

FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow vulnerability in asf_o format demuxer that can result in hea…

Fix: after 4.0.1
Fix from $1,950 2018-07-23
Ffmpeg MEDIUM 6.5
CVE-2018-1999012

FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result i…

Fix: after 4.0.1
Fix from $1,600 2018-07-23
Ffmpeg MEDIUM 6.5
CVE-2018-1999013

FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vul…

Fix: after 4.0.1
Fix from $1,600 2018-07-23
Ffmpeg MEDIUM 6.5
CVE-2018-1999014

FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in …

Fix: after 4.0.1
Fix from $1,600 2018-07-23
Ffmpeg MEDIUM 6.5
CVE-2018-1999015

FFmpeg before commit 5aba5b89d0b1d73164d3b81764828bb8b20ff32a contains an out of array read vulnerability in ASF_F format demuxer that can result in …

Fix: after 4.0.1
Fix from $1,600 2018-07-23
Ffmpeg MEDIUM 6.5
CVE-2018-14394

libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a…

Fix: 4.0.2+
Fix from $1,600 2018-07-19
Ffmpeg HIGH 8.1
CVE-2018-13305

In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function in libavcodec/vc1_block.c may…

Patch available
Fix from $1,950 2018-07-05
Ffmpeg MEDIUM 6.5
CVE-2018-13301

In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec…

Patch available
Fix from $1,600 2018-07-05
Ffmpeg MEDIUM 6.5
CVE-2018-13303

In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in libavcodec/ac3_parser.c may tri…

Patch available
Fix from $1,600 2018-07-05
Ffmpeg MEDIUM 6.5
CVE-2018-13304

In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger…

Patch available
Fix from $1,600 2018-07-05
Ffmpeg MEDIUM 6.5
CVE-2018-12459

An inconsistent bits-per-sample value in the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c in FFmpeg 4.0 may trigger an asser…

Patch available
Fix from $1,600 2018-06-15
Ffmpeg MEDIUM 6.5
CVE-2018-12460

libavcodec in FFmpeg 4.0 may trigger a NULL pointer dereference if the studio profile is incorrectly detected while converting a crafted AVI file to …

Patch available
Fix from $1,600 2018-06-15
Ffmpeg MEDIUM 6.5
CVE-2018-7751

The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a cr…

Fix: after 3.4.2
Fix from $1,600 2018-04-24
Ffmpeg HIGH 8.8
CVE-2018-9841

The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) …

Fix: after 3.4.2
Fix from $1,950 2018-04-07
Ffmpeg MEDIUM 6.5
CVE-2018-6912

The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read)…

Fix: after 3.4.2
Fix from $1,600 2018-02-12
Ffmpeg HIGH 8.8
CVE-2012-5359

Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted ASF file.

Fix: 0.11+
Fix from $1,950 2018-02-08
Ffmpeg HIGH 8.8
CVE-2012-5360

Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted QT file.

Fix: 0.11+
Fix from $1,950 2018-02-08
Ffmpeg MEDIUM 5.5
CVE-2015-1208

Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive informatio…

Fix: 2.4.6+
Fix from $1,600 2018-01-09
Ffmpeg MEDIUM 6.5
CVE-2017-9608

The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via …

Fix: 3.2.6 / 3.3.3+
Fix from $1,600 2017-12-27
Ffmpeg MEDIUM 6.5
CVE-2017-17081

The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does not properly validate widths and heights, which allows remote attack…

Patch available
Fix from $1,600 2017-11-30
Ffmpeg MEDIUM 6.5
CVE-2017-15186

Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.

Fix: after 3.3.4
Fix from $1,600 2017-10-24
Ffmpeg HIGH 8.8
CVE-2017-14767

The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allow…

Fix: after 3.3.3
Fix from $1,950 2017-09-27
Ffmpeg HIGH 8.8
CVE-2017-14225

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but c…

Patch available
Fix from $1,950 2017-09-09
Ffmpeg MEDIUM 6.5
CVE-2017-14222

In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. Whe…

Patch available
Fix from $1,600 2017-09-09
Ffmpeg MEDIUM 6.5
CVE-2017-14170

In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU …

Patch available
Fix from $1,600 2017-09-07
Ffmpeg MEDIUM 6.5
CVE-2017-14171

In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) check might cause huge CPU cons…

Patch available
Fix from $1,600 2017-09-07
Ffmpeg MEDIUM 6.5
CVE-2017-14054

In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a…

Patch available
Fix from $1,600 2017-08-31
Ffmpeg MEDIUM 6.5
CVE-2017-14055

In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumpti…

Patch available
Fix from $1,600 2017-08-31
Ffmpeg MEDIUM 6.5
CVE-2017-14056

In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumptio…

Patch available
Fix from $1,600 2017-08-31
Ffmpeg MEDIUM 6.5
CVE-2017-14057

In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF…

Patch available
Fix from $1,600 2017-08-31