![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6819
https://notcve.org/view.php?id=CVE-2015-6819
06 Sep 2015 — Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG data. Múltiples vulnerabilidades de desbordamiento inferior de entero en la función ff_mjpeg_decode_frame en libavcodec/mjpegdec.c en FFmpeg en versiones anteriores a 2.7.2, permite a atacantes remotos causar una denegación de servicio (acceso a array fuera... • http://ffmpeg.org/security.html • CWE-189: Numeric Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6822
https://notcve.org/view.php?id=CVE-2015-6822
06 Sep 2015 — The destroy_buffers function in libavcodec/sanm.c in FFmpeg before 2.7.2 does not properly maintain height and width values in the video context, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via crafted LucasArts Smush video data. Vulnerabilidad en la función destroy_buffers en libavcodec/sanm.c en FFmpeg en versiones anteriores a 2.7.2, no mantiene correctamente los valores de alto y ancho en el contexto ... • http://ffmpeg.org/security.html • CWE-17: DEPRECATED: Code •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6825
https://notcve.org/view.php?id=CVE-2015-6825
06 Sep 2015 — The ff_frame_thread_init function in libavcodec/pthread_frame.c in FFmpeg before 2.7.2 mishandles certain memory-allocation failures, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via a crafted file, as demonstrated by an AVI file. Vulnerabilidad en la función ff_frame_thread_init en libavcodec/pthread_frame.c en FFmpeg en versiones anteriores a 2.7.2, no maneja correctamente ciertos fallos de asignación de memoria, lo que permi... • http://ffmpeg.org/security.html • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6818 – Ubuntu Security Notice USN-2944-1
https://notcve.org/view.php?id=CVE-2015-6818
06 Sep 2015 — The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted image with two or more of these chunks. Vulnerabilidad en la función decode_ihdr_chunk en libavcodec/pngdec.c en FFmpeg en versiones anteriores a 2.7.2, no impone la singularidad del fragmento IHDR (también con... • http://ffmpeg.org/security.html • CWE-17: DEPRECATED: Code •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6820 – Ubuntu Security Notice USN-2944-1
https://notcve.org/view.php?id=CVE-2015-6820
06 Sep 2015 — The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted AAC data. Vulnerabilidad en la función ff_sbr_apply en libavcodec/aacsbr.c en FFmpeg en versiones anteriores a 2.7.2, no verifica la coincidencia de un elemento de sintaxis con mar... • http://ffmpeg.org/security.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6824 – Ubuntu Security Notice USN-2944-1
https://notcve.org/view.php?id=CVE-2015-6824
06 Sep 2015 — The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact via crafted video data. Vulnerabilidad en la función sws_init_context en libswscale/utils.c en FFmpeg en versiones anteriores a 2.7.2, no inicializa ciertas estructuras de datos pixbuf, lo que permite a atacantes remotos causar una denegación de servicio (vio... • http://ffmpeg.org/security.html • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6826 – Ubuntu Security Notice USN-2944-1
https://notcve.org/view.php?id=CVE-2015-6826
06 Sep 2015 — The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via crafted (1) RV30 or (2) RV40 RealVideo data. Vulnerabilidad en la función ff_rv34_decode_init_thread_copy en libavcodec/rv34.c en FFmpeg en versiones anteriores a 2.7.2, no inicializa ciertos miembros de estructura, lo que permite a atacantes rem... • http://ffmpeg.org/security.html • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-1872 – Ubuntu Security Notice USN-2944-1
https://notcve.org/view.php?id=CVE-2015-1872
26 Jul 2015 — The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of components in a JPEG-LS Start Of Frame segment, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Motion JPEG data. Vulnerabilidad en la función ff_mjpeg_decode_sof en libavcodec/mjpegdec.c en FFmpeg en versiones anteriores a 2.5.4, no valida el número de componentes en un segmento de JPEG-LS Start Of Fram... • http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=fabbfaa095660982cc0bc63242c459561fa37037 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-3417 – Gentoo Linux Security Advisory 201705-08
https://notcve.org/view.php?id=CVE-2015-3417
24 Apr 2015 — Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data. Vulnerabilidad de uso después de liberación en la función ff_h264_free_tables en libavcodec/h264.c en FFmpeg anterior a 2.3.6 permite a atacantes remotos causar una denegación de servicio o posiblemen... • http://seclists.org/fulldisclosure/2015/Apr/31 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-9676 – Gentoo Linux Security Advisory 201606-09
https://notcve.org/view.php?id=CVE-2014-9676
28 Feb 2015 — The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code via a crafted video that triggers a use after free. La función seg_write_packet en libavformat/segment.c en ffmpeg 2.1.4 y anteriores no libera la localización de memoria correcta, lo que permite a atacantes remotos causar una denegación de servicio ('manejador de... • http://seclists.org/oss-sec/2015/q1/38 •