
CVE-2017-9992 – Debian Security Advisory 4012-1
https://notcve.org/view.php?id=CVE-2017-9992
28 Jun 2017 — Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file. Buffer overflow en la memoria dinámica -heap- en la función decode_dds1 en el archivo libavcodec/dfa.c en Ffmpeg en sus versiones anteriores a la 2.8.12, 3.0.x en sus versiones anteriores a la 3... • http://www.debian.org/security/2017/dsa-4012 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9994
https://notcve.org/view.php?id=CVE-2017-9994
28 Jun 2017 — libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the vp8_decode_mb_row_no_filter and pred8x8_128_dc_8_c functions. El archivo libavcodec/webp.c en Ffmpeg en sus versiones anteriores a 2.8.12, 3.0.x en sus versiones ... • http://www.securityfocus.com/bid/99317 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9996
https://notcve.org/view.php?id=CVE-2017-9996
28 Jun 2017 — The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file. La función cdxl_decode_frame del archivo libavcodec/cdxl.c en Ffmpeg 2.8.x en sus versiones anteriores a 2.8.12, 3.0.x en sus versiones an... • http://www.securityfocus.com/bid/99323 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-7859
https://notcve.org/view.php?id=CVE-2017-7859
14 Apr 2017 — FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c. FFmpeg en versiones anteriores a 05-03-2017 tiene una escritura fuera de límites provocado por un desbordamiento de búfer basado en memoria dinámica en relación con the ff_h264_slice_context_init function in libavcodec/h264dec.c. • http://www.securityfocus.com/bid/97663 • CWE-787: Out-of-bounds Write •

CVE-2016-10190
https://notcve.org/view.php?id=CVE-2016-10190
09 Feb 2017 — Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response. Desbordamiento de búfer basado en memoria dinámica en libavformat/http.c en FFmpeg en versiones anteriores a 2.8.10, 3.0.x en versiones anteriores a 3.0.5, 3.1.x en versiones anteriores a 3.1.6 y 3.2.x en versiones anteriores a 3.2.2 permite a servidores web remotos ejecutar ... • https://github.com/muzalam/FFMPEG-exploit • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-10191
https://notcve.org/view.php?id=CVE-2016-10191
09 Feb 2017 — Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches. Desbordamiento de búfer basado en memoria dinámica en libavformat/rtmppkt.c en FFmpeg en versiones anteriores a 2.8.10, 3.0.x en versiones anteriores a 3.0.5, 3.1.x en versiones anteriores a 3.1.6 y 3.2.x en versiones anteriores a 3.2.2 permite a atacantes r... • https://github.com/KaviDk/Heap-Over-Flow-with-CVE-2016-10191 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-10192
https://notcve.org/view.php?id=CVE-2016-10192
09 Feb 2017 — Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size. Desbordamiento de búfer basado en memoria dinámica en ffserver.c en FFmpeg en versiones anteriores a 2.8.10, 3.0.x en versiones anteriores a 3.0.5, 3.1.x en versiones anteriores a 3.1.6 y 3.2.x en versiones anteriores a 3.2.2 permite a atacantes remotos ejecutar código arbitrario aprovecha... • http://www.openwall.com/lists/oss-security/2017/01/31/12 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-8595
https://notcve.org/view.php?id=CVE-2016-8595
23 Dec 2016 — The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file. La función gsm_parse en libavcodec/gsm_parser.c en FFmpeg en versiones anteriores a 3.1.5 permite a atacantes remotos provocar una denegación de servicio (fallo de asertividad) a través de un archivo AVI manipulado. • http://www.openwall.com/lists/oss-security/2016/12/08/2 • CWE-20: Improper Input Validation •

CVE-2016-9561
https://notcve.org/view.php?id=CVE-2016-9561
23 Dec 2016 — The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file. La función che_configure en libavcodec/aacdec_template.c en FFmpeg en versiones anteriores a 3.2.1 permite a atacantes remotos provocar una denegación de servicio (gran asignación de memoria y siendo aniquilado por el SO) a través de un archivo MOV manipulado. • http://www.openwall.com/lists/oss-security/2016/12/08/1 • CWE-399: Resource Management Errors •

CVE-2005-4048
https://notcve.org/view.php?id=CVE-2005-4048
07 Dec 2005 — Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes. • http://article.gmane.org/gmane.comp.video.ffmpeg.devel/26558 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •