
CVE-2017-9991
https://notcve.org/view.php?id=CVE-2017-9991
28 Jun 2017 — Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file. Buffer overflow en la memoria dinámica -heap- en la función xwd_decode_frame en el archivo libavcodec/xwddec.c en Ffmpeg en sus versiones anteriores a la 2.8.12, 3.0.x en sus versiones a... • http://www.securityfocus.com/bid/99316 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9992 – Debian Security Advisory 4012-1
https://notcve.org/view.php?id=CVE-2017-9992
28 Jun 2017 — Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file. Buffer overflow en la memoria dinámica -heap- en la función decode_dds1 en el archivo libavcodec/dfa.c en Ffmpeg en sus versiones anteriores a la 2.8.12, 3.0.x en sus versiones anteriores a la 3... • http://www.debian.org/security/2017/dsa-4012 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9994
https://notcve.org/view.php?id=CVE-2017-9994
28 Jun 2017 — libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the vp8_decode_mb_row_no_filter and pred8x8_128_dc_8_c functions. El archivo libavcodec/webp.c en Ffmpeg en sus versiones anteriores a 2.8.12, 3.0.x en sus versiones ... • http://www.securityfocus.com/bid/99317 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9995
https://notcve.org/view.php?id=CVE-2017-9995
28 Jun 2017 — libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file. El archivo libavcodec/scpr.c en Ffmpeg 3.3 anterior a la 3.3.1 no valida adecuadamente la altura y anchura de los datos, lo que permite a un atacante remoto provocar una denegación de servicio (buffer overflow basado en la pila dinámica -heap- y... • http://www.securityfocus.com/bid/99320 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9996
https://notcve.org/view.php?id=CVE-2017-9996
28 Jun 2017 — The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file. La función cdxl_decode_frame del archivo libavcodec/cdxl.c en Ffmpeg 2.8.x en sus versiones anteriores a 2.8.12, 3.0.x en sus versiones an... • http://www.securityfocus.com/bid/99323 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9993 – Debian Security Advisory 3957-1
https://notcve.org/view.php?id=CVE-2017-9993
28 Jun 2017 — FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data. Ffmpeg en sus versiones anteriores a la 2.8.12, 3.0.x y 3.1.x en sus versiones anteriores a la 3.1.9, 3.2.x en sus versiones anteriores a la 3.2.6, y 3.3.x en sus versiones anteriores a la 3.3.2 no restringe adecuadamente nombre de archivos con extensiones ... • http://www.debian.org/security/2017/dsa-3957 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2005-4048
https://notcve.org/view.php?id=CVE-2005-4048
07 Dec 2005 — Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes. • http://article.gmane.org/gmane.comp.video.ffmpeg.devel/26558 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •