CVE-2016-7450
- EPSS 0.22%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed AIFF file.
CVE-2016-7502
- EPSS 0.31%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode.
CVE-2016-7555
- EPSS 0.33%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.
CVE-2016-7562
- EPSS 0.63%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.
CVE-2016-7785
- EPSS 0.28%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
CVE-2016-7905
- EPSS 0.54%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file.
CVE-2016-8595
- EPSS 0.24%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
CVE-2016-9561
- EPSS 0.24%
- Veröffentlicht 23.12.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.
CVE-2016-3062
- EPSS 2.51%
- Veröffentlicht 16.06.2016 18:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.
CVE-2016-2330
- EPSS 0.87%
- Veröffentlicht 12.02.2016 05:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .tga file, related to t...