VYPR

rpm package

opensuse/ffmpeg-4&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweed

Vulnerabilities (92)

  • CVE-2017-7859CriApr 14, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.

  • CVE-2016-10191CriFeb 9, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.

  • CVE-2016-10190CriFeb 9, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.

  • CVE-2016-1897MedJan 15, 2016
    affected < 4.4-5.2fixed 4.4-5.2

    FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.

  • CVE-2015-8663HigDec 24, 2015
    affected < 4.4-5.2fixed 4.4-5.2

    The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.

  • CVE-2015-8661HigDec 24, 2015
    affected < 4.4-5.2fixed 4.4-5.2

    The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before 2.8.3 does not validate the relationship between the number of threads and the number of slices, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly hav

  • CVE-2015-8365Nov 26, 2015
    affected < 4.4-5.2fixed 4.4-5.2

    The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels, which allows remote attackers to cause a denial of service (out-of-bounds array

  • CVE-2015-8363Nov 26, 2015
    affected < 4.4-5.2fixed 4.4-5.2

    The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not enforce uniqueness of the SIZ marker in a JPEG 2000 image, which allows remote attackers to cause a denial of service (out-of-bounds he

  • CVE-2015-8219Nov 17, 2015
    affected < 4.4-5.2fixed 4.4-5.2

    The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordinates, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other i

  • CVE-2015-8218Nov 17, 2015
    affected < 4.4-5.2fixed 4.4-5.2

    The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data.

  • CVE-2015-8217Nov 17, 2015
    affected < 4.4-5.2fixed 4.4-5.2

    The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted High Efficien

  • CVE-2015-8216Nov 17, 2015
    affected < 4.4-5.2fixed 4.4-5.2

    The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG data.

Page 5 of 5