CVE-2022-48434
- EPSS 0.27%
- Veröffentlicht 29.03.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:33:20
libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re...
CVE-2022-3341
- EPSS 0.09%
- Veröffentlicht 12.01.2023 15:15:10
- Zuletzt bearbeitet 07.08.2025 19:26:02
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer der...
CVE-2022-3109
- EPSS 0.18%
- Veröffentlicht 16.12.2022 15:15:09
- Zuletzt bearbeitet 07.08.2025 19:26:18
An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
CVE-2022-3965
- EPSS 0.05%
- Veröffentlicht 13.11.2022 08:15:15
- Zuletzt bearbeitet 21.11.2024 07:20:37
A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads ...
CVE-2022-3964
- EPSS 0.07%
- Veröffentlicht 13.11.2022 08:15:14
- Zuletzt bearbeitet 21.11.2024 07:20:37
A vulnerability classified as problematic has been found in ffmpeg. This affects an unknown part of the file libavcodec/rpzaenc.c of the component QuickTime RPZA Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. It i...
CVE-2022-2566
- EPSS 1.47%
- Veröffentlicht 23.09.2022 12:15:10
- Zuletzt bearbeitet 21.11.2024 07:01:15
A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an inte...
CVE-2014-125023
- EPSS 0.17%
- Veröffentlicht 19.06.2022 06:15:09
- Zuletzt bearbeitet 21.11.2024 02:03:37
A vulnerability was found in FFmpeg 2.0. It has been declared as problematic. Affected by this vulnerability is the function truemotion1_decode_header of the component Truemotion1 Handler. The manipulation leads to memory corruption. The attack can b...
CVE-2014-125024
- EPSS 0.2%
- Veröffentlicht 19.06.2022 06:15:09
- Zuletzt bearbeitet 21.11.2024 02:03:37
A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function lag_decode_frame. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to f...
CVE-2014-125025
- EPSS 0.17%
- Veröffentlicht 19.06.2022 06:15:09
- Zuletzt bearbeitet 21.11.2024 02:03:37
A vulnerability classified as problematic has been found in FFmpeg 2.0. This affects the function decode_pulses. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix th...
CVE-2014-125019
- EPSS 0.17%
- Veröffentlicht 19.06.2022 06:15:08
- Zuletzt bearbeitet 21.11.2024 02:03:36
A vulnerability, which was classified as problematic, was found in FFmpeg 2.0. This affects the function decode_nal_unit of the component Slice Segment Handler. The manipulation leads to memory corruption. It is possible to initiate the attack remote...