
CVE-2013-7023 – Gentoo Linux Security Advisory 201603-06
https://notcve.org/view.php?id=CVE-2013-7023
09 Dec 2013 — The ff_combine_frame function in libavcodec/parser.c in FFmpeg before 2.1 does not properly handle certain memory-allocation errors, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data. La función ff_combine_frame en libavcodec/parser.c en FFmpeg anterior a v2.1 no maneja correctamente ciertos errores de asignación de memoria, lo que permite a atacantes remotods provocar una denegación de servicio (acceso a array ... • http://ffmpeg.org/security.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-7024 – Gentoo Linux Security Advisory 201603-06
https://notcve.org/view.php?id=CVE-2013-7024
09 Dec 2013 — The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not consider the component number in certain calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. La función jpeg2000_decode_tile en libavcodec/jpeg2000dec.c en FFmpeg anterior a v2.1 no tiene en cuenta el número de componente en ciertos cálculos, lo que permite a atacantes remotos provocar una denegación... • http://ffmpeg.org/security.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-0845 – Debian Security Advisory 2855-1
https://notcve.org/view.php?id=CVE-2013-0845
07 Dec 2013 — libavcodec/alsdec.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via a crafted block length, which triggers an out-of-bounds write. libavcodec/alsdec.c en FFmpeg anteriores a 1.0.4 permite a atacantes remotos tener un impacto no especificado a través de un bloque de longitud manipulada, lo cual activa una escritura fuera de límites. Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. • http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=0ceca269b66ec12a23bf0907bd2c220513cdbf16 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-0846 – Debian Security Advisory 2855-1
https://notcve.org/view.php?id=CVE-2013-0846
07 Dec 2013 — Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted QDM2 data, which triggers an out-of-bounds array access. Error de índice de array en la función qdm2_decode_super_block en libavcodec/qdm2.c en FFmpeg anteriores a 1.1 permite a atacantes remotos tener un impacto no especificado a través de datos QDM2 manipulados, lo cual provoca un acceso a array fuera de límites. Several security issues have ... • http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=a7ee6281f7ef1c29284e3a4cadfe0f227ffde1ed • CWE-20: Improper Input Validation •

CVE-2013-0847
https://notcve.org/view.php?id=CVE-2013-0847
07 Dec 2013 — The ff_id3v2_parse function in libavformat/id3v2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via ID3v2 header data, which triggers an out-of-bounds array access. La función ff_id3v2_parse en libavformat/id3v2.c en FFmpeg anteriores a 1.1 permite a atacantes remotos conseguir un impacto no especificado a través de información de cabecera ID3v2, lo cual activa un acceso a array fuera de límites. • http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=10416a4d56fa8a89784e4fb62099c3cab17a9952 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-0848 – Debian Security Advisory 3003-1
https://notcve.org/view.php?id=CVE-2013-0848
07 Dec 2013 — The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted width in huffyuv data with the predictor set to median and the colorspace set to YUV422P, which triggers an out-of-bounds array access. La función decode_init en libavcodec/huffyuv.c en FFmpeg anteriores a 1.1 permite a atacantes remotos tener un impacto no especificado a través de una anchura en datos huffyuv con la mediana como predictor y el espacio de colores establec... • http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=6abb9a901fca27da14d4fffbb01948288b5da3ba • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-0849 – Debian Security Advisory 2855-1
https://notcve.org/view.php?id=CVE-2013-0849
07 Dec 2013 — The roq_decode_init function in libavcodec/roqvideodec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted (1) width or (2) height dimension that is not a multiple of sixteen in id RoQ video data. La función roq_decode_init en libavcodec/roqvideodec.c en FFmpeg anterior a v1.1 permite a atacantes remotos tener un impacto no especificado a través de una dimensión manipulada de (1) ancho o (2) alto que no sea múltiple de 16 en id RoQ video. Several security issues have b... • http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=3ae610451170cd5a28b33950006ff0bd23036845 • CWE-20: Improper Input Validation •

CVE-2013-0851 – Debian Security Advisory 3003-1
https://notcve.org/view.php?id=CVE-2013-0851
07 Dec 2013 — The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which triggers an out-of-bounds array access. La función decode_frame en libavcodec/eamad.c en FFmpeg anterior a v1.1 permite a atacantes remotods tener un impacto no especificado a través de información de video Electronic Arts Madcow manipulada, lo que desencadena un acceso fuera de limites en un array. Multiple vulnerabilities have been ... • http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=63ac64864c6e0e84355aa3caa5b92208997a9a8d • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-0852 – Debian Security Advisory 3003-1
https://notcve.org/view.php?id=CVE-2013-0852
07 Dec 2013 — The parse_picture_segment function in libavcodec/pgssubdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted RLE data, which triggers an out-of-bounds array access. La función parse_picture_segment en libavcodec/pgssubdec.c en FFmpeg anterior a v1.1 permite a atacantes remotos tener un impacto no especificado a través de datos RLE manipulados, lo que desencadena un acceso fuera de limites en un array. The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.... • http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=c0d68be555f5858703383040e04fcd6529777061 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-0855
https://notcve.org/view.php?id=CVE-2013-0855
07 Dec 2013 — Integer overflow in the alac_decode_close function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a large number of samples per frame in Apple Lossless Audio Codec (ALAC) data, which triggers an out-of-bounds array access. Desbordamiento de entero en la función alac_decode_close en libavcodec/alac.c en FFmpeg anteriores a 1.1 permite a atacantes remotos tener un impacto no especificado a través de un gran número de muestras por frame en datos Apple Lossle... • http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=3920d1387834e2bc334aff9f518f4beb24e470bd • CWE-189: Numeric Errors •