Show filters
435 Total Results
Displaying 11-20 of 435
Sort by:
Attacker Value
Unknown

CVE-2021-28429

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial of service (DoS) via crafted .mov file.
Attacker Value
Unknown

CVE-2020-36138

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).
Attacker Value
Unknown

CVE-2023-39018

Disclosure Date: July 28, 2023 (last updated April 11, 2024)
FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no realistic use cases in which FFmpeg.java uses untrusted input for the path of the executable file.
Attacker Value
Unknown

CVE-2022-48434

Disclosure Date: March 29, 2023 (last updated October 08, 2023)
libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).
Attacker Value
Unknown

CVE-2022-3341

Disclosure Date: January 12, 2023 (last updated October 08, 2023)
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash.
Attacker Value
Unknown

CVE-2022-3109

Disclosure Date: December 16, 2022 (last updated October 08, 2023)
An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
Attacker Value
Unknown

CVE-2022-3964

Disclosure Date: November 13, 2022 (last updated December 22, 2023)
A vulnerability classified as problematic has been found in ffmpeg. This affects an unknown part of the file libavcodec/rpzaenc.c of the component QuickTime RPZA Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. It is possible to initiate the attack remotely. The name of the patch is 92f9b28ed84a77138105475beba16c146bdaf984. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213543.
Attacker Value
Unknown

CVE-2022-3965

Disclosure Date: November 13, 2022 (last updated December 22, 2023)
A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b36ed8edd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213544.
Attacker Value
Unknown

CVE-2022-2566

Disclosure Date: August 27, 2022 (last updated October 08, 2023)
A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc()`. An attacker can cause remote code execution via a malicious mp4 file. We recommend upgrading past commit c953baa084607dd1d84c3bfcce3cf6a87c3e6e05
Attacker Value
Unknown

CVE-2020-28435

Disclosure Date: July 25, 2022 (last updated October 07, 2023)
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.