CVE-2017-15186
- EPSS 0.55%
- Veröffentlicht 24.10.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
CVE-2017-14767
- EPSS 0.58%
- Veröffentlicht 27.09.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allows remote attackers to cause a denial of service (heap buffer overflow) or possibly have unspecified o...
CVE-2017-14225
- EPSS 0.38%
- Veröffentlicht 09.09.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, ...
CVE-2017-14222
- EPSS 0.42%
- Veröffentlicht 09.09.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which claims a large "item_count" field in the header but does not contain suff...
CVE-2017-14223
- EPSS 0.73%
- Veröffentlicht 09.09.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, which claims a large "ict" field in the header but does not contain suff...
CVE-2017-14169
- EPSS 0.24%
- Veröffentlicht 07.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided. As a result, the variable "item_n...
CVE-2017-14170
- EPSS 0.42%
- Veröffentlicht 07.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims a large "nb_index_entries" field in the header but...
CVE-2017-14171
- EPSS 0.42%
- Veröffentlicht 07.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted NSV file, which claims a large "table_entries_used" field in the header but d...
CVE-2017-14054
- EPSS 0.45%
- Veröffentlicht 31.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted IVR file, which claims a large "len" field in the header but does not contain sufficient bac...
CVE-2017-14055
- EPSS 0.45%
- Veröffentlicht 31.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large "nb_frames" field in the header but does not contain...