In Libav 12.3, there is a segmentation fault in vc1decodebmbintfr in vc1block.c that allows an attacker to cause denial-of-service via a crafted file.
In Libav 12.3, there is a heap-based buffer over-read in vc1decodepmbintfi in vc1block.c that allows an attacker to cause denial-of-service via a crafted file.
In Libav 12.3, there is a heap-based buffer over-read in vc1decodebmbintfi in vc1block.c that allows an attacker to cause denial-of-service via a crafted file.
Integer overflow in the getlen function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.2 allows remote attackers to execute arbitrary code via a crafted Literal Run.
A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srttoass in libavcodec/srtdec.c misuses snprintf.
DISPUTED A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srttoass in libavcodec/srtdec.c misuses snprintf. NOTE: Third parties dispute that this is a vulnerability because “no evidence of a vulnerability is provided” and only “a generic warning from a static code analysis” is provided.
In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srttoass in libavcodec/srtdec.c has a complex format argument to sscanf.
An issue was discovered in Libav 12.3. Division by zero in rangedecodeculshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.
In mpc8readheader in libavformat/mpc8.c in Libav 12.3, an input file can result in an avioseek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to cause a denial of service via a crafted file.
DISPUTED An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ffmpasynthfilterfloat in avcodec/mpegaudiodsptemplate.c. NOTE: This may be a duplicate of CVE-2018-19129.
In Libav 12.3, there is an infinite loop in the function wvreadblockheader() in the file wvdec.c.
An issue was discovered in Libav 12.3. There is an infinite loop in the function movprobe in the file libavformat/mov.c, related to offset and tag.
In libavcodec in Libav 9.21, ffh264executerefpicmarking() has a heap-based buffer over-read.
There exists a heap-based buffer overflow in vc1decodeiblockadv in vc1block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
There exists a heap-based buffer over-read in ffvc1preddc in vc1block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
There exists a heap-based buffer overflow in vc1decodepmbintfi in vc1block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
There exists a NULL pointer dereference in ffvc1parseframeheaderadv in vc1.c in Libav 12.3, which allows attackers to cause a denial-of-service through a crafted aac file.
An issue was discovered in Libav 12.3. A read access violation in the intableinit16 function in libavcodec/aacsbr.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.
An issue was discovered in Libav 12.3. A read access violation in the movprobe function in libavformat/mov.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.
The pcmencodeframe function in libavcodec/pcm.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted media file.
The avaudiofifosize function in libavutil/audiofifo.c in Libav 12.2 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted media file.
The mpc8probe function in libavformat/mpc8.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted audio file.
The stereoprocessing function in libavcodec/aacps.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file, related to ffpsapply.
The applydependentcoupling function in libavcodec/aacdec.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file.
The unpackparseunit function in libavcodec/diracparser.c in Libav 12.2 allows remote attackers to cause a denial of service (segmentation fault) via a crafted file.
In line libavcodec/h264dec.c:500 in libav(v13dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of initgetbits is ignored and getuegolomb(&gb) is called on an uninitialized getbits context, which causes a NULL deref exception.
There is a heap-based buffer overflow in the function hpelmotion in mpegvideomotion.c in libav 12.1. A crafted input can lead to a remote denial of service attack.
The putnorndpixels8xy2mmx function in x86/rndtemplate.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file.
The movreaddref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.
The ffh263decodemba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.