CVE-2016-10191
- EPSS 16.18%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatch...
CVE-2016-10192
- EPSS 12.51%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.
CVE-2016-6920
- EPSS 1.69%
- Veröffentlicht 23.01.2017 21:59:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of service (application crash) via vectors involving tile positions.
CVE-2016-6164
- EPSS 0.94%
- Veröffentlicht 23.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving sample size.
CVE-2016-6671
- EPSS 0.58%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted SWF file.
CVE-2016-6881
- EPSS 0.44%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file.
CVE-2016-7122
- EPSS 0.19%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure.
CVE-2016-7450
- EPSS 0.22%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed AIFF file.
CVE-2016-7502
- EPSS 0.31%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode.
CVE-2016-7555
- EPSS 0.33%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.