CVE-2017-14169
- EPSS 0.24%
- Veröffentlicht 07.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided. As a result, the variable "item_n...
CVE-2017-14170
- EPSS 0.42%
- Veröffentlicht 07.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims a large "nb_index_entries" field in the header but...
CVE-2017-14171
- EPSS 0.42%
- Veröffentlicht 07.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted NSV file, which claims a large "table_entries_used" field in the header but d...
CVE-2017-14054
- EPSS 0.45%
- Veröffentlicht 31.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted IVR file, which claims a large "len" field in the header but does not contain sufficient bac...
CVE-2017-14055
- EPSS 0.45%
- Veröffentlicht 31.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large "nb_frames" field in the header but does not contain...
CVE-2017-14056
- EPSS 0.45%
- Veröffentlicht 31.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted RL2 file, which claims a large "frame_count" field in the header but does not conta...
CVE-2017-14057
- EPSS 0.45%
- Veröffentlicht 31.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient...
CVE-2017-14058
- EPSS 0.88%
- Veröffentlicht 31.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote attackers to cause a denial of service (infinite loop).
CVE-2017-14059
- EPSS 0.58%
- Veröffentlicht 31.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. When a crafted CINE file, which claims a large "duration" field in the header but does not contain sufficient backing data, is provi...
CVE-2012-2805
- EPSS 0.5%
- Veröffentlicht 28.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Unspecified vulnerability in FFMPEG 0.10 allows remote attackers to cause a denial of service.