Ffmpeg

Ffmpeg

548 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.31%
  • Veröffentlicht 14.10.2019 02:15:10
  • Zuletzt bearbeitet 21.11.2024 04:32:29

FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c.

Exploit
  • EPSS 2.02%
  • Veröffentlicht 05.09.2019 16:15:12
  • Zuletzt bearbeitet 21.11.2024 04:29:47

FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcodec/h2645_parse.c mishandles rbsp_buffer.

Exploit
  • EPSS 1.7%
  • Veröffentlicht 07.07.2019 22:15:10
  • Zuletzt bearbeitet 21.11.2024 04:24:50

In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat/rawenc.c.

  • EPSS 1.69%
  • Veröffentlicht 05.07.2019 01:15:11
  • Zuletzt bearbeitet 21.11.2024 04:24:41

block_cmp() in libavcodec/zmbvenc.c in FFmpeg 4.1.3 has a heap-based buffer over-read.

  • EPSS 3.03%
  • Veröffentlicht 04.06.2019 14:29:01
  • Zuletzt bearbeitet 21.11.2024 04:23:27

aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.

  • EPSS 2.35%
  • Veröffentlicht 19.04.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:54

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via c...

  • EPSS 2.75%
  • Veröffentlicht 19.04.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:54

The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via crafted MPEG-4 video dat...

  • EPSS 1.57%
  • Veröffentlicht 12.03.2019 09:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:10

In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.

  • EPSS 1.44%
  • Veröffentlicht 12.03.2019 09:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:10

A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.

  • EPSS 1.12%
  • Veröffentlicht 04.02.2019 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:17:41

FFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability in libavcodec/cbs_av1.c that can result in Denial of service. This attack appears to be exploitable via specially crafted AV1 file has to be provided as input. Th...