CVE-2015-6819
- EPSS 0.52%
- Veröffentlicht 06.09.2015 02:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted M...
CVE-2015-6818
- EPSS 1.03%
- Veröffentlicht 06.09.2015 02:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a denial of service (out-of-bounds array access) or p...
CVE-2015-1872
- EPSS 0.62%
- Veröffentlicht 26.07.2015 22:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of components in a JPEG-LS Start Of Frame segment, which allows remote attackers to cause a denial of service (out-of-bounds array access) o...
CVE-2015-3395
- EPSS 0.79%
- Veröffentlicht 16.06.2015 16:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via...
CVE-2015-3417
- EPSS 1.02%
- Veröffentlicht 24.04.2015 17:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demo...
CVE-2014-9676
- EPSS 1.61%
- Veröffentlicht 28.02.2015 01:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code vi...
CVE-2014-7937
- EPSS 2.21%
- Veröffentlicht 22.01.2015 22:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Vorb...
CVE-2014-7933
- EPSS 5.94%
- Veröffentlicht 22.01.2015 22:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other...
CVE-2014-9604
- EPSS 0.65%
- Veröffentlicht 16.01.2015 20:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video d...
CVE-2014-9603
- EPSS 0.91%
- Veröffentlicht 16.01.2015 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (out-of-bounds array access) or ...