CVE-2017-9991
- EPSS 0.46%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (appli...
CVE-2017-9992
- EPSS 0.7%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application c...
CVE-2017-9993
- EPSS 56.17%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist d...
CVE-2017-9994
- EPSS 0.42%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow ...
CVE-2017-9995
- EPSS 0.38%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via...
CVE-2017-9996
- EPSS 0.39%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial ...
CVE-2017-7859
- EPSS 0.99%
- Veröffentlicht 14.04.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.
CVE-2017-7862
- EPSS 1.66%
- Veröffentlicht 14.04.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c.
CVE-2017-7863
- EPSS 1.88%
- Veröffentlicht 14.04.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.
CVE-2017-7865
- EPSS 1.88%
- Veröffentlicht 14.04.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c.