Search CVE reports


Toggle filters

81 – 90 of 332 results


CVE-2018-19129

Low priority
Vulnerable

In Libav 12.3, a NULL pointer dereference (RIP points to zero) issue in ff_mpa_synth_filter_float in libavcodec/mpegaudiodsp_template.c can cause a segmentation fault (application crash) via a crafted mov file.

1 affected package

libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-19128

Low priority
Vulnerable

In Libav 12.3, there is a heap-based buffer over-read in decode_frame in libavcodec/lcldec.c that allows an attacker to cause denial-of-service via a crafted avi file.

1 affected package

libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-18829

Medium priority
Needs evaluation

There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers to cause a denial-of-service through a crafted aac file.

5 affected packages

libav, vlc, qtwebengine-opensource-src, gst-libav1.0, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18828

Medium priority
Needs evaluation

There exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

5 affected packages

vlc, libav, qtwebengine-opensource-src, gst-libav1.0, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18827

Medium priority
Needs evaluation

There exists a heap-based buffer over-read in ff_vc1_pred_dc in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

5 affected packages

vlc, libav, qtwebengine-opensource-src, gst-libav1.0, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18826

Medium priority
Needs evaluation

There exists a heap-based buffer overflow in vc1_decode_p_mb_intfi in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

5 affected packages

vlc, gst-libav1.0, libav, qtwebengine-opensource-src, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Not affected
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release Not in release Not in release
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-14395

Low priority

Some fixes available 2 of 3

libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted audio file when converting to the MOV audio format.

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Fixed
libav Not in release
Show less packages

CVE-2018-14394

Low priority

Some fixes available 12 of 14

libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted Waveform audio file.

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release Not in release Not in release
ffmpeg Fixed Fixed Fixed Fixed
Show less packages

CVE-2018-13305

Medium priority
Needs evaluation

In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function in libavcodec/vc1_block.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4,...

7 affected packages

chromium-browser, gst-libav1.0, mythtv, oxide-qt, libav...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Ignored Ignored Not in release Ignored
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation
oxide-qt Not in release Not in release Not in release Not in release
libav Not in release Not in release Not in release Not in release
ffmpeg Not affected Not affected Not affected Not affected
vlc Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages

CVE-2018-13304

Medium priority
Needs evaluation

In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger an assertion failure while converting a crafted AVI file to MPEG4, leading to a...

12 affected packages

chromium-browser, dvbcut, gst-libav1.0, kino, mplayer...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Ignored Ignored Not in release Ignored
dvbcut Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kino Not in release Needs evaluation Needs evaluation Needs evaluation
mplayer Not affected Not affected Not affected Not affected
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation
oxide-qt Not in release Not in release Not in release Not in release
xine-lib Not in release Not in release Not in release Not in release
libav Not in release Not in release Not in release Not in release
ffmpeg Not affected Not affected Not affected Not affected
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected
Show all 12 packages Show less packages