Show filters
109 Total Results
Displaying 1-10 of 109
Sort by:
Attacker Value
Unknown

CVE-2020-18778

Disclosure Date: August 23, 2021 (last updated November 29, 2024)
In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Attacker Value
Unknown

CVE-2020-18775

Disclosure Date: August 23, 2021 (last updated November 29, 2024)
In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Attacker Value
Unknown

CVE-2020-18776

Disclosure Date: August 23, 2021 (last updated November 29, 2024)
In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Attacker Value
Unknown

CVE-2020-36407

Disclosure Date: July 01, 2021 (last updated November 28, 2024)
libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
Attacker Value
Unknown

CVE-2014-4609

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.2 allows remote attackers to execute arbitrary code via a crafted Literal Run.
Attacker Value
Unknown

CVE-2019-9717

Disclosure Date: September 19, 2019 (last updated November 27, 2024)
In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex format argument to sscanf.
Attacker Value
Unknown

CVE-2019-9719

Disclosure Date: September 19, 2019 (last updated November 08, 2023)
A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf. NOTE: Third parties dispute that this is a vulnerability because “no evidence of a vulnerability is provided” and only “a generic warning from a static code analysis” is provided
Attacker Value
Unknown

CVE-2019-9720

Disclosure Date: September 19, 2019 (last updated November 27, 2024)
A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.
Attacker Value
Unknown

CVE-2019-14443

Disclosure Date: July 30, 2019 (last updated November 27, 2024)
An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.
Attacker Value
Unknown

CVE-2019-14441

Disclosure Date: July 30, 2019 (last updated November 08, 2023)
An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ff_mpa_synth_filter_float in avcodec/mpegaudiodsp_template.c. NOTE: This may be a duplicate of CVE-2018-19129