In libass 0.14.0, the assoutlineconstruct's call to outlinestroke causes a signed integer overflow.
Stack overflow in the parsetag function in libass/assparse.c in libass before 0.15.0 allows remote attackers to cause a denial of service or remote code execution via a crafted file.
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decodechars (called from decodefont and processtext) because the wrong integer data type is used for subtraction.