Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ffmpeg HIGH 7.5
CVE-2014-8546

Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possi…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ffmpeg HIGH 7.5
CVE-2014-8549

libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of channels to at most 2, which allows remote attackers to cause a denial of…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ffmpeg MEDIUM 6.8
CVE-2014-5272

libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote attackers to have unspecified …

Fix: after 1.1.13
Fix from $1,600 2014-11-03
Ffmpeg HIGH 7.5
CVE-2014-5271

Heap-based buffer overflow in the encode_slice function in libavcodec/proresenc_kostya.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.x before 2.2.…

Fix: after 10.4
Fix from $1,950 2014-11-03
Ffmpeg MEDIUM 6.8
CVE-2014-2097

The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows …

Fix: after 2.1.3
Fix from $1,600 2014-03-02
Ffmpeg MEDIUM 6.8
CVE-2014-2098

libavcodec/wmalosslessdec.c in FFmpeg before 2.1.4 uses an incorrect data-structure size for certain coefficients, which allows remote attackers to c…

Fix: after 2.1.3
Fix from $1,600 2014-03-02
Ffmpeg MEDIUM 6.8
CVE-2014-2099

The msrle_decode_frame function in libavcodec/msrle.c in FFmpeg before 2.1.4 does not properly calculate line sizes, which allows remote attackers to…

Fix: after 2.1.3
Fix from $1,600 2014-03-02
Ffmpeg MEDIUM 6.8
CVE-2014-2263

The mpegts_write_pmt function in the MPEG2 transport stream (aka DVB) muxer (libavformat/mpegtsenc.c) in FFmpeg, possibly 2.1 and earlier, allows rem…

Fix: after 2.1
Fix from $1,600 2014-03-01
Ffmpeg MEDIUM 5.0
CVE-2012-6616

The mov_text_decode_frame function in libavcodec/movtextdec.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (out-of-bou…

Fix: after 1.0.1
Fix from $1,600 2013-12-24
Ffmpeg MEDIUM 5.0
CVE-2013-4358

libavcodec/h264.c in FFmpeg before 0.11.4 allows remote attackers to cause a denial of service (crash) via vectors related to alternating bit depths …

Fix: after 0.11.3
Fix from $1,600 2013-12-24
Ffmpeg MEDIUM 6.8
CVE-2013-7021

The filter_frame function in libavfilter/vf_fps.c in FFmpeg before 2.1 does not properly ensure the availability of FIFO content, which allows remote…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7022

The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 does not properly allocate memory for tiles, which allows remote attackers …

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7023

The ff_combine_frame function in libavcodec/parser.c in FFmpeg before 2.1 does not properly handle certain memory-allocation errors, which allows rem…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7024

The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not consider the component number in certain calculations, wh…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7015

The flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before 2.1 does not properly validate a certain height value, which allows remote…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7016

The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the expected sample separation, which allows remote attackers t…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7017

libavcodec/jpeg2000.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) or possibly have unspec…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7018

libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the use of valid code-block dimension values, which allows remote attackers to cause a …

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7019

The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers …

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7010

Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds ar…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7011

The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not prevent changes to global parameters, which allows remote attackers to…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7012

The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not prevent attempts to use non-zero image offsets, which allows remote at…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7013

The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote at…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7014

Integer signedness error in the add_bytes_l2_c function in libavcodec/pngdsp.c in FFmpeg before 2.1 allows remote attackers to cause a denial of serv…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7008

The decode_slice_header function in libavcodec/h264.c in FFmpeg before 2.1 incorrectly relies on a certain droppable field, which allows remote attac…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7009

The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows remote att…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg HIGH 7.5
CVE-2011-4351

Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before 0.7.8, and 0.8.x before 0.8.8 allows remote attackers to execute arbitrary c…

Fix: after 0.5.5
Fix from $1,950 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2011-3950

The dirac_decode_data_unit function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via a crafte…

Fix: after 0.9.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2011-3949

The dirac_unpack_idwt_params function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafte…

Fix: after 0.9.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2011-3946EPSS 6%

The ff_h264_decode_sei function in libavcodec/h264_sei.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Supp…

Fix: after 0.9.1
Fix from $1,600 2013-12-09