CVE-2017-7866
- EPSS 1.64%
- Veröffentlicht 14.04.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c.
CVE-2012-5361
- EPSS 1.86%
- Veröffentlicht 20.03.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file.
CVE-2016-10190
- EPSS 10.19%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.
CVE-2016-10191
- EPSS 8.66%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatch...
CVE-2016-10192
- EPSS 5.54%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.
CVE-2016-6920
- EPSS 1.69%
- Veröffentlicht 23.01.2017 21:59:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of service (application crash) via vectors involving tile positions.
CVE-2016-6164
- EPSS 0.94%
- Veröffentlicht 23.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving sample size.
CVE-2016-6671
- EPSS 0.58%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted SWF file.
CVE-2016-6881
- EPSS 0.44%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file.
CVE-2016-7122
- EPSS 0.19%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure.