Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2014-7933 |
Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska file that triggers improper maintenance of tracks data. Published: January 22, 2015; 5:59:14 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-9604 |
libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video data, related to the (1) restore_median and (2) restore_median_il functions. Published: January 16, 2015; 3:59:02 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-9603 |
The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Sierra VMD video data. Published: January 16, 2015; 3:59:01 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-9602 |
libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relationship, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted X-Face image data. Published: January 16, 2015; 3:59:00 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-8549 |
libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of channels to at most 2, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted On2 data. Published: November 05, 2014; 6:55:08 AM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-8548 |
Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime Graphics (aka SMC) video data. Published: November 05, 2014; 6:55:08 AM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-8547 |
libavcodec/gifdec.c in FFmpeg before 2.4.2 does not properly compute image heights, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted GIF data. Published: November 05, 2014; 6:55:08 AM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-8546 |
Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Cinepak video data. Published: November 05, 2014; 6:55:08 AM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-8545 |
libavcodec/pngdec.c in FFmpeg before 2.4.2 accepts the monochrome-black format without verifying that the bits-per-pixel value is 1, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted PNG data. Published: November 05, 2014; 6:55:08 AM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-8544 |
libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted TIFF data. Published: November 05, 2014; 6:55:07 AM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-8543 |
libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MM video data. Published: November 05, 2014; 6:55:07 AM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-8542 |
libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data. Published: November 05, 2014; 6:55:07 AM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2014-8541 |
libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension differences, and not bits-per-pixel differences, when determining whether an image size has changed, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MJPEG data. Published: November 05, 2014; 6:55:07 AM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |