Vulnerabilities
Vulnerable Software
Ffmpeg:  >> Ffmpeg  >> 4.1.2  Security Vulnerabilities
FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c.
CVSS Score
9.8
EPSS Score
0.008
Published
2019-10-14
FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcodec/h2645_parse.c mishandles rbsp_buffer.
CVSS Score
8.8
EPSS Score
0.005
Published
2019-09-05
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.
CVSS Score
8.8
EPSS Score
0.02
Published
2019-04-19


Contact Us

Shodan ® - All rights reserved