Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2020-20448

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
FFmpeg 4.1.3 is affected by a Divide By Zero issue via libavcodec/ratecontrol.c, which allows a remote malicious user to cause a Denial of Service.
Attacker Value
Unknown

CVE-2020-21041

Disclosure Date: May 24, 2021 (last updated February 22, 2025)
Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service
Attacker Value
Unknown

CVE-2020-12284

Disclosure Date: April 28, 2020 (last updated February 21, 2025)
cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check.
Attacker Value
Unknown

CVE-2019-13390

Disclosure Date: July 07, 2019 (last updated November 27, 2024)
In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat/rawenc.c.
0
Attacker Value
Unknown

CVE-2019-13312

Disclosure Date: July 05, 2019 (last updated November 27, 2024)
block_cmp() in libavcodec/zmbvenc.c in FFmpeg 4.1.3 has a heap-based buffer over-read.
0
Attacker Value
Unknown

CVE-2019-11338

Disclosure Date: April 19, 2019 (last updated November 27, 2024)
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.
Attacker Value
Unknown

CVE-2019-9721

Disclosure Date: March 12, 2019 (last updated November 27, 2024)
A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
Attacker Value
Unknown

CVE-2019-9718

Disclosure Date: March 12, 2019 (last updated November 27, 2024)
In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
Attacker Value
Unknown

CVE-2019-1000016

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
FFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability in libavcodec/cbs_av1.c that can result in Denial of service. This attack appears to be exploitable via specially crafted AV1 file has to be provided as input. This vulnerability appears to have been fixed in after commit b97a4b658814b2de8b9f2a3bce491c002d34de31.
0