Vulnerabilities > Ffmpeg > High

DATE CVE VULNERABILITY TITLE RISK
2017-06-28 CVE-2017-9996 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
local
low complexity
ffmpeg CWE-119
7.8
2017-06-28 CVE-2017-9995 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg 3.3
libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
local
low complexity
ffmpeg CWE-119
7.8
2017-06-28 CVE-2017-9994 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the vp8_decode_mb_row_no_filter and pred8x8_128_dc_8_c functions.
local
low complexity
ffmpeg debian CWE-119
7.8
2017-06-28 CVE-2017-9993 Information Exposure vulnerability in multiple products
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
network
low complexity
ffmpeg debian CWE-200
7.5
2017-06-28 CVE-2017-9992 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
network
low complexity
ffmpeg debian CWE-119
8.8
2017-06-28 CVE-2017-9991 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
local
low complexity
ffmpeg CWE-119
7.8
2017-06-28 CVE-2017-9990 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
Stack-based buffer overflow in the color_string_to_rgba function in libavcodec/xpmdec.c in FFmpeg 3.3 before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
network
low complexity
ffmpeg CWE-119
8.8
2017-03-20 CVE-2012-5361 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file.
local
low complexity
ffmpeg CWE-119
7.8
2017-01-23 CVE-2016-6920 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of service (application crash) via vectors involving tile positions.
network
low complexity
ffmpeg CWE-119
7.5
2016-12-23 CVE-2016-7502 Out-of-bounds Read vulnerability in Ffmpeg
The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode.
local
low complexity
ffmpeg CWE-125
7.8