
CVE-2013-7009 – Gentoo Linux Security Advisory 201603-06
https://notcve.org/view.php?id=CVE-2013-7009
09 Dec 2013 — The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Apple RPZA data. La función rpza_decode_stream en libavcodec/rpza.c en FFmpeg anteriores a 2.1 no mantiene correctamente un puntero a píxeles, lo cual permite a atacantes remotos causar denegación de servicio (acceso a array fuera de límites) o... • http://ffmpeg.org/security.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-7013 – Gentoo Linux Security Advisory 201603-06
https://notcve.org/view.php?id=CVE-2013-7013
09 Dec 2013 — The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Go2Webinar data. La función g2m_init_buffers en libavcodec/g2meet.c en FFmpeg anterior a v2.1 utiliza un incorrecto orden de las operaciones ariméticas, lo que permite a atacantes remotos provocar una denegación de servicio (acceso a array fue... • http://ffmpeg.org/security.html • CWE-189: Numeric Errors •

CVE-2013-7021 – Gentoo Linux Security Advisory 201603-06
https://notcve.org/view.php?id=CVE-2013-7021
09 Dec 2013 — The filter_frame function in libavfilter/vf_fps.c in FFmpeg before 2.1 does not properly ensure the availability of FIFO content, which allows remote attackers to cause a denial of service (double free) or possibly have unspecified other impact via crafted data. La funcióm filter_frame en libavfilter/vf_fps.c en FFmepg anteriores a 2.1 no asegura apropiadamente la disponibilidad de contenido FIFO, lo que permite a atacantes remotos causar una denegación de servicio (doble liberación) o posiblemente tener ot... • http://ffmpeg.org/security.html • CWE-399: Resource Management Errors •

CVE-2013-7014 – Debian Security Advisory 2855-1
https://notcve.org/view.php?id=CVE-2013-7014
09 Dec 2013 — Integer signedness error in the add_bytes_l2_c function in libavcodec/pngdsp.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted PNG data. Error de signo en la función add_bytes_l2c de libavcodec/pngdsp.c en FFmepg anteriores a 2.1 permite a atacantes remotos causar una denegación de servicio (acceso a array fuera de rango) o posiblemente tener un impacto no especificado a través de datos PNG manipulad... • http://ffmpeg.org/security.html • CWE-189: Numeric Errors •

CVE-2013-7017 – Gentoo Linux Security Advisory 201603-06
https://notcve.org/view.php?id=CVE-2013-7017
09 Dec 2013 — libavcodec/jpeg2000.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via crafted JPEG2000 data. libavcodec/jpeg2000.c en FFmpeg anterior a la versión 2.1 permite a atacantes remotos provocar una denegación de servicio (referencia a puntero inválido) o posiblemente tener otro impacto sin especificar a través de datos JPEG2000 manipulados. Multiple vulnerabilities have been found in FFmpeg, the worst of which co... • http://ffmpeg.org/security.html •

CVE-2013-7008 – Gentoo Linux Security Advisory 201603-06
https://notcve.org/view.php?id=CVE-2013-7008
09 Dec 2013 — The decode_slice_header function in libavcodec/h264.c in FFmpeg before 2.1 incorrectly relies on a certain droppable field, which allows remote attackers to cause a denial of service (deadlock) or possibly have unspecified other impact via crafted H.264 data. La función decode_slice_header en libavcodec/h264.c en FFmpeg anteriores a 2.1 depende incorrectamente de cierto campo deshechable, lo que permite a atacantes remotos causar una denegación de servico (deadlock) o posiblemente tener otro impacto no espe... • http://ffmpeg.org/security.html •

CVE-2013-7022 – Gentoo Linux Security Advisory 201603-06
https://notcve.org/view.php?id=CVE-2013-7022
09 Dec 2013 — The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 does not properly allocate memory for tiles, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Go2Webinar data. La función g2m_init_buffers en libavcodec/g2meet.c en FFmpeg anterior a v2.1 no maneja correctamente la memoria para mosaicos, lo que permite a atacantes remotos provocar una denegación de servicio (acceso a array fuera de rango) o po... • http://ffmpeg.org/security.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-0846 – Debian Security Advisory 2855-1
https://notcve.org/view.php?id=CVE-2013-0846
07 Dec 2013 — Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted QDM2 data, which triggers an out-of-bounds array access. Error de índice de array en la función qdm2_decode_super_block en libavcodec/qdm2.c en FFmpeg anteriores a 1.1 permite a atacantes remotos tener un impacto no especificado a través de datos QDM2 manipulados, lo cual provoca un acceso a array fuera de límites. Several security issues have ... • http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=a7ee6281f7ef1c29284e3a4cadfe0f227ffde1ed • CWE-20: Improper Input Validation •

CVE-2013-0851 – Debian Security Advisory 3003-1
https://notcve.org/view.php?id=CVE-2013-0851
07 Dec 2013 — The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which triggers an out-of-bounds array access. La función decode_frame en libavcodec/eamad.c en FFmpeg anterior a v1.1 permite a atacantes remotods tener un impacto no especificado a través de información de video Electronic Arts Madcow manipulada, lo que desencadena un acceso fuera de limites en un array. Multiple vulnerabilities have been ... • http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=63ac64864c6e0e84355aa3caa5b92208997a9a8d • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-0856
https://notcve.org/view.php?id=CVE-2013-0856
07 Dec 2013 — The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nb_samples value. La función lpc_prediction en libavcodec/alac.c en FFmpeg anteriores a 1.1 permite a atacantes remotos tener un impacto no especificado a través de datos Apple Lossless Audio Codec (ALAC), relacionado con un valor nb_samples grande. • http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=fd4f4923cce6a2cbf4f48640b4ac706e614a1594 • CWE-20: Improper Input Validation •