Vulnerabilities > Ffmpeg

DATE CVE VULNERABILITY TITLE RISK
2018-04-07 CVE-2018-9841 Out-of-bounds Read vulnerability in Ffmpeg
The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a long filename.
network
low complexity
ffmpeg CWE-125
8.8
2018-02-28 CVE-2018-7557 Out-of-bounds Read vulnerability in multiple products
The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array read) via an AVI file with crafted dimensions within chroma subsampling data.
network
low complexity
ffmpeg debian CWE-125
6.5
2018-02-12 CVE-2018-6912 Out-of-bounds Read vulnerability in Ffmpeg
The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.
network
ffmpeg CWE-125
4.3
2018-02-08 CVE-2012-5360 Improper Input Validation vulnerability in Ffmpeg
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted QT file.
network
ffmpeg CWE-20
critical
9.3
2018-02-08 CVE-2012-5359 Improper Input Validation vulnerability in Ffmpeg
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted ASF file.
network
ffmpeg CWE-20
critical
9.3
2018-02-05 CVE-2018-6621 Out-of-bounds Read vulnerability in multiple products
The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.
4.3
2018-01-29 CVE-2018-6392 Out-of-bounds Read vulnerability in multiple products
The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows remote attackers to cause a denial of service (out-of-array access) via a crafted MP4 file.
4.3
2018-01-09 CVE-2015-1208 Integer Underflow (Wrap or Wraparound) vulnerability in Ffmpeg
Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.
local
low complexity
ffmpeg CWE-191
5.5
2018-01-03 CVE-2017-1000460 NULL Pointer Dereference vulnerability in multiple products
In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.
4.3
2017-12-27 CVE-2017-9608 NULL Pointer Dereference vulnerability in Ffmpeg
The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.
network
ffmpeg CWE-476
4.3