CVE-2015-6819
- EPSS 0.52%
- Published 06.09.2015 02:59:01
- Last modified 12.04.2025 10:46:40
Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted M...
CVE-2015-6818
- EPSS 1.03%
- Published 06.09.2015 02:59:00
- Last modified 12.04.2025 10:46:40
The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a denial of service (out-of-bounds array access) or p...
CVE-2015-1872
- EPSS 0.62%
- Published 26.07.2015 22:59:01
- Last modified 12.04.2025 10:46:40
The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of components in a JPEG-LS Start Of Frame segment, which allows remote attackers to cause a denial of service (out-of-bounds array access) o...
CVE-2015-3395
- EPSS 0.79%
- Published 16.06.2015 16:59:04
- Last modified 12.04.2025 10:46:40
The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via...
CVE-2015-3417
- EPSS 1.02%
- Published 24.04.2015 17:59:03
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demo...
CVE-2014-9676
- EPSS 1.61%
- Published 28.02.2015 01:59:00
- Last modified 12.04.2025 10:46:40
The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code vi...
CVE-2014-7937
- EPSS 2.21%
- Published 22.01.2015 22:59:18
- Last modified 12.04.2025 10:46:40
Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Vorb...
CVE-2014-7933
- EPSS 5.94%
- Published 22.01.2015 22:59:14
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other...
CVE-2014-9604
- EPSS 0.65%
- Published 16.01.2015 20:59:02
- Last modified 12.04.2025 10:46:40
libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video d...
CVE-2014-9603
- EPSS 0.91%
- Published 16.01.2015 20:59:01
- Last modified 12.04.2025 10:46:40
The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (out-of-bounds array access) or ...