Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2016-7555
The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted…
Ffmpeg
after 3.1.3
MEDIUM 5.5
CVE-2016-7562
The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) v…
Ffmpeg
after 3.1.3
MEDIUM 5.5
CVE-2016-7785
The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a c…
Ffmpeg
after 3.1.3
MEDIUM 5.5
CVE-2016-7905
The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) vi…
Ffmpeg
after 3.1.3
MEDIUM 5.5
CVE-2016-8595
The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a cr…
Ffmpeg
after 3.1.4
MEDIUM 5.5
CVE-2016-9561
The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of…
Ffmpeg
after 3.2
HIGH 8.8
CVE-2016-2328
libswscale/swscale_unscaled.c in FFmpeg before 2.8.6 does not validate certain height values, which allows remote attackers to cause a denial of serv…
Ffmpeg
after 2.8.5
HIGH 8.8
CVE-2016-2327
libavcodec/pngenc.c in FFmpeg before 2.8.5 uses incorrect line sizes in certain row calculations, which allows remote attackers to cause a denial of …
Ffmpeg
after 2.8.4
MEDIUM 6.5
CVE-2016-2213
The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a denial of service (out-of-bou…
Ffmpeg
after 2.8.5
HIGH 8.3
CVE-2015-8663
The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attack…
Ffmpeg
Mitigation only
HIGH 8.3
CVE-2015-8661
The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before 2.8.3 does not validate the relationship between the number of thread…
Ffmpeg
after 2.8.2
HIGH 7.3
CVE-2015-8662
The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does not validate the number of decomposition levels before proceeding …
Ffmpeg
after 2.8.3
MEDIUM 6.8
CVE-2015-8363
The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not enfo…
Ffmpeg
Mitigation only
HIGH 7.5
CVE-2015-8219
The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordi…
Ffmpeg
after 2.8.1
MEDIUM 6.8
CVE-2015-8218
The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers t…
Ffmpeg
after 2.8.1
HIGH 7.5
CVE-2015-8217
The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote atta…
Ffmpeg
after 2.8.1
HIGH 7.5
CVE-2015-8216
The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attacke…
Ffmpeg
after 2.8.1
HIGH 7.5
CVE-2015-6825
The ff_frame_thread_init function in libavcodec/pthread_frame.c in FFmpeg before 2.7.2 mishandles certain memory-allocation failures, which allows re…
Ffmpeg
after 2.7.1
HIGH 7.5
CVE-2015-6823
The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does not initialize certain context data, which allows remote attackers to …
Ffmpeg
after 2.7.1
HIGH 7.5
CVE-2015-6822
The destroy_buffers function in libavcodec/sanm.c in FFmpeg before 2.7.2 does not properly maintain height and width values in the video context, whi…
Ffmpeg
after 2.7.1
HIGH 7.5
CVE-2015-6821
The ff_mpv_common_init function in libavcodec/mpegvideo.c in FFmpeg before 2.7.2 does not properly maintain the encoding context, which allows remote…
Ffmpeg
after 2.7.1
HIGH 7.5
CVE-2015-6819
Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow remote attackers to cause a d…
Ffmpeg
after 2.7.1
MEDIUM 6.8
CVE-2014-9676
The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote att…
Ffmpeg
after 2.1.4
HIGH 7.5
CVE-2014-9603
The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the fra…
Ffmpeg
after 2.5.1
HIGH 7.5
CVE-2014-9602
libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relations…
Ffmpeg
after 2.5.1
MEDIUM 5.0
CVE-2014-9319
The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attacke…
Ffmpeg
after 2.1.5
HIGH 7.5
CVE-2014-9318
The raw_decode function in libavcodec/rawdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a…
Ffmpeg
after 2.1.5
HIGH 7.5
CVE-2014-9317
The decode_ihdr_chunk function in libavcodec/pngdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to …
Ffmpeg
after 2.1.5
HIGH 7.5
CVE-2014-9316
The mjpeg_decode_app function in libavcodec/mjpegdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to…
Ffmpeg
after 2.1.5
HIGH 7.5
CVE-2014-8545
libavcodec/pngdec.c in FFmpeg before 2.4.2 accepts the monochrome-black format without verifying that the bits-per-pixel value is 1, which allows rem…
Ffmpeg
after 2.4.1