Vulnerabilities > Ffmpeg

DATE CVE VULNERABILITY TITLE RISK
2008-11-01 CVE-2008-4867 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ffmpeg
Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.
network
low complexity
ffmpeg mplayer CWE-119
critical
10.0
2008-11-01 CVE-2008-4866 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ffmpeg
Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY.
network
low complexity
ffmpeg mplayer CWE-119
critical
10.0
2008-07-18 CVE-2008-3230 Improper Input Validation vulnerability in Ffmpeg Lavf Demuxer
The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by lol-giftopnm.gif.
local
ffmpeg CWE-20
1.9
2008-07-14 CVE-2008-3162 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ffmpeg
Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted STR file that interleaves audio and video sectors.
network
ffmpeg CWE-119
critical
9.3
2006-09-14 CVE-2006-4800 Buffer Overflow vulnerability in FFmpeg Image File
Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c.
network
low complexity
ffmpeg
7.5
2005-12-07 CVE-2005-4048 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ffmpeg
Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.
network
low complexity
ffmpeg CWE-119
7.5