
CVE-2017-9993 – Debian Security Advisory 3957-1
https://notcve.org/view.php?id=CVE-2017-9993
28 Jun 2017 — FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data. Ffmpeg en sus versiones anteriores a la 2.8.12, 3.0.x y 3.1.x en sus versiones anteriores a la 3.1.9, 3.2.x en sus versiones anteriores a la 3.2.6, y 3.3.x en sus versiones anteriores a la 3.3.2 no restringe adecuadamente nombre de archivos con extensiones ... • http://www.debian.org/security/2017/dsa-3957 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-9990
https://notcve.org/view.php?id=CVE-2017-9990
28 Jun 2017 — Stack-based buffer overflow in the color_string_to_rgba function in libavcodec/xpmdec.c in FFmpeg 3.3 before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file. Buffer overflow basado en pila -stack- en la función color_string_to_rgba en el archivo libavcodec/xpmdec.c en Ffmpeg 3.3.x en sus versiones anteriores a la 3.3.1 permite a un atacante remoto causar una denegación de servicio (caída de la aplicación) u otro posi... • http://www.securityfocus.com/bid/99313 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9991
https://notcve.org/view.php?id=CVE-2017-9991
28 Jun 2017 — Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file. Buffer overflow en la memoria dinámica -heap- en la función xwd_decode_frame en el archivo libavcodec/xwddec.c en Ffmpeg en sus versiones anteriores a la 2.8.12, 3.0.x en sus versiones a... • http://www.securityfocus.com/bid/99316 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9992 – Debian Security Advisory 4012-1
https://notcve.org/view.php?id=CVE-2017-9992
28 Jun 2017 — Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file. Buffer overflow en la memoria dinámica -heap- en la función decode_dds1 en el archivo libavcodec/dfa.c en Ffmpeg en sus versiones anteriores a la 2.8.12, 3.0.x en sus versiones anteriores a la 3... • http://www.debian.org/security/2017/dsa-4012 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9994
https://notcve.org/view.php?id=CVE-2017-9994
28 Jun 2017 — libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the vp8_decode_mb_row_no_filter and pred8x8_128_dc_8_c functions. El archivo libavcodec/webp.c en Ffmpeg en sus versiones anteriores a 2.8.12, 3.0.x en sus versiones ... • http://www.securityfocus.com/bid/99317 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-9996
https://notcve.org/view.php?id=CVE-2017-9996
28 Jun 2017 — The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file. La función cdxl_decode_frame del archivo libavcodec/cdxl.c en Ffmpeg 2.8.x en sus versiones anteriores a 2.8.12, 3.0.x en sus versiones an... • http://www.securityfocus.com/bid/99323 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-7859
https://notcve.org/view.php?id=CVE-2017-7859
14 Apr 2017 — FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c. FFmpeg en versiones anteriores a 05-03-2017 tiene una escritura fuera de límites provocado por un desbordamiento de búfer basado en memoria dinámica en relación con the ff_h264_slice_context_init function in libavcodec/h264dec.c. • http://www.securityfocus.com/bid/97663 • CWE-787: Out-of-bounds Write •

CVE-2017-7862 – Gentoo Linux Security Advisory 201811-19
https://notcve.org/view.php?id=CVE-2017-7862
14 Apr 2017 — FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c. FFmpeg en versiones anteriores a 07-02-2017 tiene una escritura fuera de límites provocado por un desbordamiento de búfer basado en memoria dinámica en relación con la función decode_frame en libavcodec/pictordec.c Multiple vulnerabilities have been found in Libav, the worst of which may allow a Denial of Service condition. Versions less than 12.3 are aff... • http://www.debian.org/security/2017/dsa-4012 • CWE-787: Out-of-bounds Write •

CVE-2017-7863
https://notcve.org/view.php?id=CVE-2017-7863
14 Apr 2017 — FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c. FFmpeg en versiones anteriores a 04-02-2017 tiene una escritura fuera de límites provocado por un desbordamiento de búfer basado en memoria dinámica en relación con la función decode_frame_common en libavcodec/pngdec.c • http://www.securityfocus.com/bid/97675 • CWE-787: Out-of-bounds Write •

CVE-2017-7865
https://notcve.org/view.php?id=CVE-2017-7865
14 Apr 2017 — FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c. FFmpeg en versiones anteriores a 24-01-2017 tiene una escritura fuera de límites provocado por un desbordamiento de búfer basado en memoria dinámica en relación con la función ipvideo_decode_block_opcode_0xA en libavcodec/interplayvideo.c unad la función avcodec_align... • http://www.securityfocus.com/bid/97685 • CWE-787: Out-of-bounds Write •