Vulnerabilities
Vulnerable Software
Ffmpeg:  >> Ffmpeg  >> 3.1.8  Security Vulnerabilities
Stack-based buffer overflow in the color_string_to_rgba function in libavcodec/xpmdec.c in FFmpeg 3.3 before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
CVSS Score
8.8
EPSS Score
0.026
Published
2017-06-28
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
CVSS Score
7.5
EPSS Score
0.164
Published
2017-06-28
FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.
CVSS Score
9.8
EPSS Score
0.019
Published
2017-04-14
The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.
CVSS Score
5.5
EPSS Score
0.011
Published
2016-12-23


Contact Us

Shodan ® - All rights reserved