9.3

CVE-2013-0867

The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remote attackers to have unspecified impact via crafted H.264 video data, related to an out-of-bounds array access.

Data is provided by the National Vulnerability Database (NVD)
FfmpegFfmpeg Version <= 1.1.1
FfmpegFfmpeg Version0.3
FfmpegFfmpeg Version0.3.1
FfmpegFfmpeg Version0.3.2
FfmpegFfmpeg Version0.3.3
FfmpegFfmpeg Version0.3.4
FfmpegFfmpeg Version0.4.0
FfmpegFfmpeg Version0.4.2
FfmpegFfmpeg Version0.4.3
FfmpegFfmpeg Version0.4.4
FfmpegFfmpeg Version0.4.5
FfmpegFfmpeg Version0.4.6
FfmpegFfmpeg Version0.4.7
FfmpegFfmpeg Version0.4.8
FfmpegFfmpeg Version0.4.9 Updatepre1
FfmpegFfmpeg Version0.5
FfmpegFfmpeg Version0.5.1
FfmpegFfmpeg Version0.5.2
FfmpegFfmpeg Version0.5.3
FfmpegFfmpeg Version0.5.4
FfmpegFfmpeg Version0.5.4.5
FfmpegFfmpeg Version0.5.4.6
FfmpegFfmpeg Version0.6
FfmpegFfmpeg Version0.6.1
FfmpegFfmpeg Version0.6.2
FfmpegFfmpeg Version0.6.3
FfmpegFfmpeg Version0.7
FfmpegFfmpeg Version0.7.1
FfmpegFfmpeg Version0.7.2
FfmpegFfmpeg Version0.7.3
FfmpegFfmpeg Version0.7.4
FfmpegFfmpeg Version0.7.5
FfmpegFfmpeg Version0.7.6
FfmpegFfmpeg Version0.7.7
FfmpegFfmpeg Version0.7.8
FfmpegFfmpeg Version0.7.9
FfmpegFfmpeg Version0.7.11
FfmpegFfmpeg Version0.7.12
FfmpegFfmpeg Version0.8.0
FfmpegFfmpeg Version0.8.1
FfmpegFfmpeg Version0.8.2
FfmpegFfmpeg Version0.8.5
FfmpegFfmpeg Version0.8.5.3
FfmpegFfmpeg Version0.8.5.4
FfmpegFfmpeg Version0.8.6
FfmpegFfmpeg Version0.8.7
FfmpegFfmpeg Version0.8.8
FfmpegFfmpeg Version0.8.10
FfmpegFfmpeg Version0.8.11
FfmpegFfmpeg Version0.9
FfmpegFfmpeg Version0.9.1
FfmpegFfmpeg Version0.10
FfmpegFfmpeg Version0.10.3
FfmpegFfmpeg Version0.10.4
FfmpegFfmpeg Version0.11
FfmpegFfmpeg Version1.0
FfmpegFfmpeg Version1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.71% 0.7
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.