Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ffmpeg MEDIUM 6.5
CVE-2017-14058

In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote …

Patch available
Fix from $1,600 2017-08-31
Ffmpeg MEDIUM 6.5
CVE-2017-14059

In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. When a crafted CINE file, which…

Patch available
Fix from $1,600 2017-08-31
Ffmpeg CRITICAL 9.8
CVE-2013-0870

The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.

No fix yet
Fix from $2,300 2017-08-28
Ffmpeg HIGH 7.5
CVE-2012-2805

Unspecified vulnerability in FFMPEG 0.10 allows remote attackers to cause a denial of service.

No fix yet
Fix from $1,950 2017-08-28
Ffmpeg CRITICAL 9.8
CVE-2012-2771

Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2773, CVE-2012-2778,…

Fix: 0.10.3+
Fix from $2,300 2017-08-09
Ffmpeg CRITICAL 9.8
CVE-2012-2773

Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2778,…

Fix: after 0.10.0
Fix from $2,300 2017-08-09
Ffmpeg CRITICAL 9.8
CVE-2012-2778

Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773,…

Fix: after 0.10.0
Fix from $2,300 2017-08-09
Ffmpeg CRITICAL 9.8
CVE-2012-2780

Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773,…

Fix: after 0.10.0
Fix from $2,300 2017-08-09
Ffmpeg CRITICAL 9.8
CVE-2012-2781

Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773,…

Fix: after 0.10.0
Fix from $2,300 2017-08-09
Ffmpeg HIGH 7.8
CVE-2017-11719

The dnxhd_decode_header function in libavcodec/dnxhddec.c in FFmpeg 3.0 through 3.3.2 allows remote attackers to cause a denial of service (out-of-ar…

Fix: after 3.3.2
Fix from $1,950 2017-07-28
Ffmpeg HIGH 7.5
CVE-2017-11665

The ff_amf_get_field_value function in libavformat/rtmppkt.c in FFmpeg 3.3.2 allows remote RTMP servers to cause a denial of service (Segmentation Vi…

Patch available
Fix from $1,950 2017-07-27
Ffmpeg HIGH 7.8
CVE-2017-11399

Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg 2.4 through 3.3.2 allows remote attackers to cause a denial of ser…

Fix: after 3.3.2
Fix from $1,950 2017-07-17
Ffmpeg HIGH 8.8
CVE-2017-9990

Stack-based buffer overflow in the color_string_to_rgba function in libavcodec/xpmdec.c in FFmpeg 3.3 before 3.3.1 allows remote attackers to cause a…

Fix: after 3.3
Fix from $1,950 2017-06-28
Ffmpeg HIGH 7.8
CVE-2017-9991

Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3…

Fix: after 2.8.11
Fix from $1,950 2017-06-28
Ffmpeg HIGH 7.8
CVE-2017-9995

libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of ser…

Patch available
Fix from $1,950 2017-06-28
Ffmpeg HIGH 7.8
CVE-2017-9996

The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.…

Patch available
Fix from $1,950 2017-06-28
Ffmpeg CRITICAL 9.8
CVE-2017-7859

FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in liba…

Fix: after 3.2.4
Fix from $2,300 2017-04-14
Ffmpeg CRITICAL 9.8
CVE-2017-7862

FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictord…

Fix: after 2.8.10
Fix from $2,300 2017-04-14
Ffmpeg CRITICAL 9.8
CVE-2017-7866

FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.…

Fix: after 2.8.9
Fix from $2,300 2017-04-14
Ffmpeg HIGH 7.8
CVE-2012-5361

Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file.

Fix: after 0.10.15
Fix from $1,950 2017-03-20
Ffmpeg CRITICAL 9.8
CVE-2016-10190EPSS 8%

Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remot…

Fix: after 2.8.9
Fix from $2,300 2017-02-09
Ffmpeg CRITICAL 9.8
CVE-2016-10191EPSS 7%

Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows re…

Fix: after 2.8.9
Fix from $2,300 2017-02-09
Ffmpeg CRITICAL 9.8
CVE-2016-10192EPSS 6%

Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attack…

Fix: after 2.8.9
Fix from $2,300 2017-02-09
Ffmpeg HIGH 7.5
CVE-2016-6920

Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of servi…

Fix: after 3.1.2
Fix from $1,950 2017-01-23
Ffmpeg CRITICAL 9.8
CVE-2016-6164

Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote…

Fix: after 2.8.7
Fix from $2,300 2017-01-23
Ffmpeg HIGH 7.8
CVE-2016-6671

The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of service (memory corruption) or exe…

Fix: after 3.1.1
Fix from $1,950 2016-12-23
Ffmpeg HIGH 7.8
CVE-2016-7450

The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed …

Fix: after 3.1.3
Fix from $1,950 2016-12-23
Ffmpeg HIGH 7.8
CVE-2016-7502

The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_de…

Fix: after 3.1.3
Fix from $1,950 2016-12-23
Ffmpeg MEDIUM 5.5
CVE-2016-6881

The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a cra…

Fix: after 3.1.2
Fix from $1,600 2016-12-23
Ffmpeg MEDIUM 5.5
CVE-2016-7122

The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a craf…

Fix: after 3.1.3
Fix from $1,600 2016-12-23