Search CVE reports
151 – 160 of 479 results
CVE-2018-1999015
Medium priorityFFmpeg before commit 5aba5b89d0b1d73164d3b81764828bb8b20ff32a contains an out of array read vulnerability in ASF_F format demuxer that can result in heap memory reading. This attack appear to be exploitable via specially crafted...
2 affected packages
ffmpeg, gst-libav1.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ffmpeg | Not affected | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2018-1999014
Medium priorityFFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which...
7 affected packages
chromium-browser, ffmpeg, gst-libav1.0, kino, oxide-qt...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
chromium-browser | Ignored | Ignored | Ignored | Ignored | Ignored |
ffmpeg | Not affected | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
kino | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release | Ignored |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
vlc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2018-1999013
Medium priorityFFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to...
5 affected packages
chromium-browser, ffmpeg, gst-libav1.0, oxide-qt, qtwebengine-opensource-src
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
chromium-browser | Ignored | Ignored | Ignored | Ignored | Ignored |
ffmpeg | Not affected | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release | Ignored |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
CVE-2018-1999012
Medium prioritySome fixes available 1 of 58
FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in a Vulnerability that allows attackers to consume excessive amount of resources...
8 affected packages
chromium-browser, ffmpeg, gst-libav1.0, kino, libav...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
chromium-browser | Ignored | Ignored | Ignored | Ignored | Ignored |
ffmpeg | Not affected | Not affected | Not affected | Not affected | Fixed |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
kino | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libav | Not in release | Not in release | Not in release | Not in release | Not in release |
oxide-qt | Not in release | Not in release | Not in release | Not in release | Ignored |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
vlc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2018-1999011
Medium priorityFFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow vulnerability in asf_o format demuxer that can result in heap-buffer-overflow that may result in remote code execution. This attack appears...
6 affected packages
chromium-browser, ffmpeg, gst-libav1.0, oxide-qt, qtwebengine-opensource-src, vlc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
chromium-browser | Ignored | Ignored | Ignored | Ignored | Ignored |
ffmpeg | Not affected | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release | Ignored |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
vlc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2018-1999010
Medium prioritySome fixes available 1 of 48
FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable...
7 affected packages
chromium-browser, ffmpeg, gst-libav1.0, libav, oxide-qt...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
chromium-browser | Ignored | Ignored | Ignored | Ignored | Ignored |
ffmpeg | Not affected | Not affected | Not affected | Not affected | Fixed |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libav | Not in release | Not in release | Not in release | Not in release | Not in release |
oxide-qt | Not in release | Not in release | Not in release | Not in release | Ignored |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
vlc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2018-14395
Low prioritySome fixes available 2 of 3
libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted audio file when converting to the MOV audio format.
2 affected packages
ffmpeg, libav
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ffmpeg | — | — | — | Fixed | Not affected |
libav | — | — | — | Not in release | Not in release |
CVE-2018-14394
Low prioritySome fixes available 11 of 13
libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted Waveform audio file.
2 affected packages
ffmpeg, libav
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ffmpeg | Fixed | Fixed | Fixed | Fixed | Fixed |
libav | Not in release | Not in release | Not in release | Not in release | Not in release |
CVE-2018-13305
Medium priorityIn FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function in libavcodec/vc1_block.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4,...
7 affected packages
chromium-browser, ffmpeg, gst-libav1.0, libav, mythtv...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
chromium-browser | Ignored | Ignored | Ignored | Ignored | Ignored |
ffmpeg | Not affected | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libav | Not in release | Not in release | Not in release | Not in release | Not in release |
mythtv | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release | Ignored |
vlc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2018-13304
Medium priorityIn libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger an assertion failure while converting a crafted AVI file to MPEG4, leading to a...
13 affected packages
chromium-browser, dvbcut, ffmpeg, gst-libav1.0, gstreamer0.10-ffmpeg...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
chromium-browser | Ignored | Ignored | Ignored | Ignored | Ignored |
dvbcut | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ffmpeg | Not affected | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gstreamer0.10-ffmpeg | Not in release | Not in release | Not in release | Not in release | Not in release |
kino | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libav | Not in release | Not in release | Not in release | Not in release | Not in release |
mplayer | Not affected | Not affected | Not affected | Not affected | Not affected |
mythtv | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release | Ignored |
vice | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vlc | Not affected | Not affected | Not affected | Not affected | Not affected |
xine-lib | Not in release | Not in release | Not in release | Not in release | Not in release |