VYPR

Libav

by Libav

Source repositories

CVEs (108)

  • CVE-2017-1000460MedJan 3, 2018
    risk 0.42cvss 6.5epss 0.00

    In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.

  • CVE-2017-17128MedDec 4, 2017
    risk 0.42cvss 6.5epss 0.01

    The h264_slice_init function in libavcodec/h264_slice.c in Libav 12.2 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted file.

  • CVE-2017-17127MedDec 4, 2017
    risk 0.42cvss 6.5epss 0.02

    The vc1_decode_frame function in libavcodec/vc1dec.c in Libav 12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

  • CVE-2015-5479MedApr 19, 2016
    risk 0.42cvss 6.5epss 0.02

    The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.

  • CVE-2016-9826MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.01

    libavcodec/ituh263dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

  • CVE-2016-9825MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.01

    libswscale/utils.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

  • CVE-2016-9824MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.01

    Integer overflow in libswscale/x86/swscale.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2016-9823MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.01

    libavcodec/x86/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2016-9822MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.01

    Integer overflow in libavcodec/mpeg12dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2016-9821MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.01

    Integer overflow in libavcodec/mpegvideo_parser.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2016-9820MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.01

    libavcodec/mpegvideo_motion.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

  • CVE-2016-9819MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.01

    libavcodec/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

  • CVE-2016-8676MedFeb 15, 2017
    risk 0.36cvss 5.5epss 0.02

    The get_vlc2 function in get_bits.h in Libav 11.9 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted mp3 file. NOTE: this issue exists due to an incomplete fix for CVE-2016-8675.

  • CVE-2016-8675MedFeb 15, 2017
    risk 0.36cvss 5.5epss 0.02

    The get_vlc2 function in get_bits.h in Libav before 11.9 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted mp3 file, possibly related to startcode sequences during m4v detection.

  • CVE-2016-7499MedFeb 15, 2017
    risk 0.36cvss 5.5epss 0.01

    The sbr_make_f_master function in aacsbr.c in Libav 11.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.

  • CVE-2016-7477MedFeb 15, 2017
    risk 0.36cvss 5.5epss 0.02

    The ff_put_pixels8_xy2_mmx function in rnd_template.c in Libav 11.7 allows remote attackers to cause a denial of service (invalid memory access and crash) via a crafted mp3 file. NOTE: this issue was originally reported as involving a NULL pointer dereference.

  • CVE-2016-7393MedFeb 15, 2017
    risk 0.36cvss 5.5epss 0.02

    Stack-based buffer overflow in the aac_sync function in aac_parser.c in Libav before 11.5 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

  • CVE-2016-6832MedFeb 15, 2017
    risk 0.36cvss 5.5epss 0.02

    Heap-based buffer overflow in the ff_audio_resample function in resample.c in libav before 11.4 allows remote attackers to cause a denial of service (crash) via vectors related to buffer resizing.

  • CVE-2016-7424MedOct 7, 2016
    risk 0.36cvss 5.5epss 0.02

    The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file.

  • CVE-2025-8585MedAug 5, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double free. Attacking locally is a requirement. The…

Page 3 of 6