CVE-2017-9608
- EPSS 8.94%
- Veröffentlicht 27.12.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.
CVE-2017-17555
- EPSS 0.36%
- Veröffentlicht 12.12.2017 01:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash)...
CVE-2017-17081
- EPSS 0.53%
- Veröffentlicht 30.11.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does not properly validate widths and heights, which allows remote attackers to cause a denial of service (integer signedness error and out-of-array read) via a crafted MPEG ...
CVE-2017-16840
- EPSS 1.59%
- Veröffentlicht 21.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related to libavcodec/vc2enc.c and libavcodec/vc2enc_dwt.c.
CVE-2017-15672
- EPSS 1.16%
- Veröffentlicht 06.11.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via a crafted MP4 file, which triggers an out-of-bounds read.
CVE-2017-15186
- EPSS 0.55%
- Veröffentlicht 24.10.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
CVE-2017-14767
- EPSS 0.67%
- Veröffentlicht 27.09.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allows remote attackers to cause a denial of service (heap buffer overflow) or possibly have unspecified o...
CVE-2017-14225
- EPSS 0.36%
- Veröffentlicht 09.09.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, ...
CVE-2017-14222
- EPSS 0.42%
- Veröffentlicht 09.09.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which claims a large "item_count" field in the header but does not contain suff...
CVE-2017-14223
- EPSS 0.85%
- Veröffentlicht 09.09.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, which claims a large "ict" field in the header but does not contain suff...