Search CVE reports
171 – 180 of 521 results
FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to...
5 affected packages
chromium-browser, oxide-qt, ffmpeg, qtwebengine-opensource-src, gst-libav1.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 1 of 60
FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in a Vulnerability that allows attackers to consume excessive amount of resources...
8 affected packages
chromium-browser, gst-libav1.0, kino, oxide-qt, ffmpeg...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
kino | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vlc | Not affected | Not affected | Not affected | Not affected |
libav | Not in release | Not in release | Not in release | Not in release |
FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow vulnerability in asf_o format demuxer that can result in heap-buffer-overflow that may result in remote code execution. This attack appears...
6 affected packages
chromium-browser, gst-libav1.0, oxide-qt, ffmpeg, qtwebengine-opensource-src, vlc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vlc | Not affected | Not affected | Not affected | Not affected |
Some fixes available 1 of 50
FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable...
7 affected packages
chromium-browser, gst-libav1.0, oxide-qt, ffmpeg, qtwebengine-opensource-src...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vlc | Not affected | Not affected | Not affected | Not affected |
libav | Not in release | Not in release | Not in release | Not in release |
There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers to cause a denial-of-service through a crafted aac file.
5 affected packages
libav, vlc, qtwebengine-opensource-src, gst-libav1.0, ffmpeg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libav | Not in release | Not in release | Not in release | Not in release |
vlc | Not affected | Not affected | Not affected | Not affected |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
There exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
5 affected packages
vlc, libav, qtwebengine-opensource-src, gst-libav1.0, ffmpeg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
vlc | Not affected | Not affected | Not affected | Not affected |
libav | Not in release | Not in release | Not in release | Not in release |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
There exists a heap-based buffer over-read in ff_vc1_pred_dc in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
5 affected packages
vlc, libav, qtwebengine-opensource-src, gst-libav1.0, ffmpeg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
vlc | Not affected | Not affected | Not affected | Not affected |
libav | Not in release | Not in release | Not in release | Not in release |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
There exists a heap-based buffer overflow in vc1_decode_p_mb_intfi in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
5 affected packages
vlc, gst-libav1.0, libav, qtwebengine-opensource-src, ffmpeg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
vlc | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libav | Not in release | Not in release | Not in release | Not in release |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.
1 affected package
ffmpeg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ffmpeg | — | — | Not affected | Fixed |
Some fixes available 2 of 3
libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted audio file when converting to the MOV audio format.
2 affected packages
ffmpeg, libav
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ffmpeg | — | — | — | Fixed |
libav | — | — | — | Not in release |