Ffmpeg

Ffmpeg

486 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.82%
  • Veröffentlicht 12.02.2016 05:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PTS (aka presentation timestamp) value in a ...

  • EPSS 0.68%
  • Veröffentlicht 03.02.2016 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a denial of service (out-of-bounds array read access) via crafted JPEG 2000 data.

Exploit
  • EPSS 57.76%
  • Veröffentlicht 15.01.2016 03:59:23
  • Zuletzt bearbeitet 12.04.2025 10:46:40

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of...

Exploit
  • EPSS 33.19%
  • Veröffentlicht 15.01.2016 03:59:23
  • Zuletzt bearbeitet 12.04.2025 10:46:40

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary lin...

  • EPSS 0.68%
  • Veröffentlicht 24.12.2015 01:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impa...

  • EPSS 0.68%
  • Veröffentlicht 24.12.2015 01:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before 2.8.3 does not validate the relationship between the number of threads and the number of slices, which allows remote attackers to cause a denial of service (out-of-bounds...

  • EPSS 0.68%
  • Veröffentlicht 24.12.2015 01:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does not validate the number of decomposition levels before proceeding with Discrete Wavelet Transform decoding, which allows remote attackers to cause a denial of service ...

  • EPSS 0.54%
  • Veröffentlicht 26.11.2015 17:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels, which allows remote attackers to cause a denial o...

  • EPSS 0.58%
  • Veröffentlicht 26.11.2015 17:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspe...

  • EPSS 0.49%
  • Veröffentlicht 26.11.2015 17:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not enforce uniqueness of the SIZ marker in a JPEG 2000 image, which allows remote attackers to cause a denia...