CVE-2013-7008
- EPSS 1.41%
- Published 09.12.2013 16:36:47
- Last modified 11.04.2025 00:51:21
The decode_slice_header function in libavcodec/h264.c in FFmpeg before 2.1 incorrectly relies on a certain droppable field, which allows remote attackers to cause a denial of service (deadlock) or possibly have unspecified other impact via crafted H....
CVE-2013-7009
- EPSS 1.41%
- Published 09.12.2013 16:36:47
- Last modified 11.04.2025 00:51:21
The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other i...
CVE-2011-4351
- EPSS 2.81%
- Published 09.12.2013 16:36:43
- Last modified 11.04.2025 00:51:21
Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before 0.7.8, and 0.8.x before 0.8.8 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2011-3950
- EPSS 0.59%
- Published 09.12.2013 16:36:25
- Last modified 11.04.2025 00:51:21
The dirac_decode_data_unit function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via a crafted value in the reference pictures number.
CVE-2011-3949
- EPSS 0.59%
- Published 09.12.2013 16:36:09
- Last modified 11.04.2025 00:51:21
The dirac_unpack_idwt_params function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Dirac data.
CVE-2011-3946
- EPSS 0.59%
- Published 09.12.2013 16:35:44
- Last modified 11.04.2025 00:51:21
The ff_h264_decode_sei function in libavcodec/h264_sei.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Supplemental enhancement information (SEI) data, which triggers an infinite loop.
CVE-2011-3944
- EPSS 0.66%
- Published 09.12.2013 16:35:18
- Last modified 11.04.2025 00:51:21
The smacker_decode_header_tree function in libavcodec/smacker.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Smacker data.
CVE-2011-3941
- EPSS 0.63%
- Published 09.12.2013 16:34:56
- Last modified 11.04.2025 00:51:21
The decode_mb function in libavcodec/error_resilience.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via vectors related to an uninitialized block index, which triggers an out-of-bounds write.
CVE-2011-3935
- EPSS 0.59%
- Published 09.12.2013 16:34:28
- Last modified 11.04.2025 00:51:21
The codec_get_buffer function in ffmpeg.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via vectors related to a crafted image size.
CVE-2011-3934
- EPSS 0.59%
- Published 09.12.2013 16:34:00
- Last modified 11.04.2025 00:51:21
Double free vulnerability in the vp3_update_thread_context function in libavcodec/vp3.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted vp3 data.