Vulnerabilities > Ffmpeg

DATE CVE VULNERABILITY TITLE RISK
2017-03-20 CVE-2012-5361 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file.
local
low complexity
ffmpeg CWE-119
7.8
2017-02-09 CVE-2016-10192 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.
network
low complexity
ffmpeg CWE-119
critical
9.8
2017-02-09 CVE-2016-10191 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.
network
low complexity
ffmpeg CWE-119
critical
9.8
2017-02-09 CVE-2016-10190 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.
network
low complexity
ffmpeg CWE-119
critical
9.8
2017-01-23 CVE-2016-6920 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of service (application crash) via vectors involving tile positions.
network
low complexity
ffmpeg CWE-119
7.5
2017-01-23 CVE-2016-6164 Integer Overflow or Wraparound vulnerability in Ffmpeg
Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving sample size.
network
low complexity
ffmpeg CWE-190
critical
9.8
2016-12-23 CVE-2016-9561 Resource Management Errors vulnerability in Ffmpeg
The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.
local
low complexity
ffmpeg CWE-399
5.5
2016-12-23 CVE-2016-8595 Improper Input Validation vulnerability in Ffmpeg
The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
local
low complexity
ffmpeg CWE-20
5.5
2016-12-23 CVE-2016-7905 NULL Pointer Dereference vulnerability in Ffmpeg
The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file.
local
low complexity
ffmpeg CWE-476
5.5
2016-12-23 CVE-2016-7785 Improper Input Validation vulnerability in Ffmpeg
The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
local
low complexity
ffmpeg CWE-20
5.5