libav CVE Vulnerabilities & Metrics

Focus on libav vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About libav Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with libav. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total libav CVEs: 60
Earliest CVE date: 07 Jul 2011, 21:55 UTC
Latest CVE date: 23 Aug 2021, 22:15 UTC

Latest CVE reference: CVE-2020-18778

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical libav CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.46

Max CVSS: 10.0

Critical CVEs (≥9): 26

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 74
7.0-8.9 5
9.0-10.0 26

CVSS Distribution Chart

Top 5 Highest CVSS libav CVEs

These are the five CVEs with the highest CVSS scores for libav, sorted by severity first and recency.

All CVEs for libav

CVE-2020-18778 libav vulnerability CVSS: 4.3 23 Aug 2021, 22:15 UTC

In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.

CVE-2020-18776 libav vulnerability CVSS: 4.3 23 Aug 2021, 22:15 UTC

In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.

CVE-2020-18775 libav vulnerability CVSS: 4.3 23 Aug 2021, 22:15 UTC

In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.

CVE-2014-4609 libav vulnerability CVSS: 6.8 14 Jan 2020, 16:15 UTC

Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.2 allows remote attackers to execute arbitrary code via a crafted Literal Run.

CVE-2019-9720 libav vulnerability CVSS: 7.1 19 Sep 2019, 21:15 UTC

A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.

CVE-2019-9719 libav vulnerability CVSS: 6.8 19 Sep 2019, 21:15 UTC

A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf. NOTE: Third parties dispute that this is a vulnerability because “no evidence of a vulnerability is provided” and only “a generic warning from a static code analysis” is provided

CVE-2019-9717 libav vulnerability CVSS: 7.1 19 Sep 2019, 21:15 UTC

In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex format argument to sscanf.

CVE-2019-14443 libav vulnerability CVSS: 4.3 30 Jul 2019, 13:15 UTC

An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.

CVE-2019-14442 libav vulnerability CVSS: 7.1 30 Jul 2019, 13:15 UTC

In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to cause a denial of service via a crafted file.

CVE-2019-14441 libav vulnerability CVSS: 4.3 30 Jul 2019, 13:15 UTC

An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ff_mpa_synth_filter_float in avcodec/mpegaudiodsp_template.c. NOTE: This may be a duplicate of CVE-2018-19129

CVE-2019-14372 libav vulnerability CVSS: 4.3 28 Jul 2019, 19:15 UTC

In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.

CVE-2019-14371 libav vulnerability CVSS: 4.3 28 Jul 2019, 19:15 UTC

An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.

CVE-2017-5984 libav vulnerability CVSS: 4.3 22 May 2019, 20:29 UTC

In libavcodec in Libav 9.21, ff_h264_execute_ref_pic_marking() has a heap-based buffer over-read.

CVE-2018-20001 libav vulnerability CVSS: 4.3 10 Dec 2018, 02:29 UTC

In Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits) in libavcodec/apedec.c that will lead to remote denial of service via crafted input.

CVE-2018-19130 libav vulnerability CVSS: 4.3 09 Nov 2018, 11:29 UTC

In Libav 12.3, there is an invalid memory access in vc1_decode_frame in libavcodec/vc1dec.c that allows attackers to cause a denial-of-service via a crafted aac file. NOTE: This may be a duplicate of CVE-2017-17127

CVE-2018-19129 libav vulnerability CVSS: 4.3 09 Nov 2018, 11:29 UTC

In Libav 12.3, a NULL pointer dereference (RIP points to zero) issue in ff_mpa_synth_filter_float in libavcodec/mpegaudiodsp_template.c can cause a segmentation fault (application crash) via a crafted mov file.

CVE-2018-19128 libav vulnerability CVSS: 4.3 09 Nov 2018, 11:29 UTC

In Libav 12.3, there is a heap-based buffer over-read in decode_frame in libavcodec/lcldec.c that allows an attacker to cause denial-of-service via a crafted avi file.

CVE-2018-18829 libav vulnerability CVSS: 4.3 30 Oct 2018, 06:29 UTC

There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers to cause a denial-of-service through a crafted aac file.

CVE-2018-18828 libav vulnerability CVSS: 4.3 30 Oct 2018, 06:29 UTC

There exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

CVE-2018-18827 libav vulnerability CVSS: 4.3 30 Oct 2018, 06:29 UTC

There exists a heap-based buffer over-read in ff_vc1_pred_dc in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

CVE-2018-18826 libav vulnerability CVSS: 4.3 30 Oct 2018, 06:29 UTC

There exists a heap-based buffer overflow in vc1_decode_p_mb_intfi in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

CVE-2018-11224 libav vulnerability CVSS: 4.3 17 May 2018, 04:29 UTC

An issue was discovered in Libav 12.3. A read access violation in the in_table_init16 function in libavcodec/aacsbr.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.

CVE-2018-11102 libav vulnerability CVSS: 5.0 15 May 2018, 02:29 UTC

An issue was discovered in Libav 12.3. A read access violation in the mov_probe function in libavformat/mov.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.

CVE-2017-18247 libav vulnerability CVSS: 4.3 23 Mar 2018, 19:29 UTC

The av_audio_fifo_size function in libavutil/audio_fifo.c in Libav 12.2 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted media file.

CVE-2017-18246 libav vulnerability CVSS: 4.3 23 Mar 2018, 19:29 UTC

The pcm_encode_frame function in libavcodec/pcm.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted media file.

CVE-2017-18245 libav vulnerability CVSS: 4.3 23 Mar 2018, 19:29 UTC

The mpc8_probe function in libavformat/mpc8.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted audio file.

CVE-2017-18244 libav vulnerability CVSS: 4.3 22 Mar 2018, 21:29 UTC

The stereo_processing function in libavcodec/aacps.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file, related to ff_ps_apply.

CVE-2017-18243 libav vulnerability CVSS: 4.3 22 Mar 2018, 21:29 UTC

The unpack_parse_unit function in libavcodec/dirac_parser.c in Libav 12.2 allows remote attackers to cause a denial of service (segmentation fault) via a crafted file.

CVE-2017-18242 libav vulnerability CVSS: 4.3 22 Mar 2018, 21:29 UTC

The apply_dependent_coupling function in libavcodec/aacdec.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file.

CVE-2018-5766 libav vulnerability CVSS: 6.8 18 Jan 2018, 07:29 UTC

In Libav through 12.2, there is an invalid memcpy in the av_packet_ref function of libavcodec/avpacket.c. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted avi file.

CVE-2018-5684 libav vulnerability CVSS: 6.8 14 Jan 2018, 02:29 UTC

In Libav through 12.2, there is an invalid memcpy call in the ff_mov_read_stsd_entries function of libavformat/mov.c. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) and program failure with a crafted avi file.

CVE-2017-1000460 libav vulnerability CVSS: 4.3 03 Jan 2018, 20:29 UTC

In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.

CVE-2017-17130 libav vulnerability CVSS: 6.8 04 Dec 2017, 08:29 UTC

The ff_free_picture_tables function in libavcodec/mpegpicture.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to vc1_decode_i_blocks_adv.

CVE-2017-17129 libav vulnerability CVSS: 6.8 04 Dec 2017, 08:29 UTC

The ff_vc1_mc_4mv_chroma4 function in libavcodec/vc1_mc.c in Libav 12.2 allows remote attackers to cause a denial of service (segmentation fault and application crash) or possibly have unspecified other impact via a crafted file.

CVE-2017-17128 libav vulnerability CVSS: 4.3 04 Dec 2017, 08:29 UTC

The h264_slice_init function in libavcodec/h264_slice.c in Libav 12.2 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted file.

CVE-2017-17127 libav vulnerability CVSS: 4.3 04 Dec 2017, 08:29 UTC

The vc1_decode_frame function in libavcodec/vc1dec.c in Libav 12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

CVE-2017-16803 libav vulnerability CVSS: 5.0 13 Nov 2017, 17:29 UTC

In Libav through 11.11 and 12.x through 12.1, the smacker_decode_tree function in libavcodec/smacker.c does not properly restrict tree recursion, which allows remote attackers to cause a denial of service (bitstream.c:build_table() out-of-bounds read and application crash) via a crafted Smacker stream.

CVE-2017-11684 libav vulnerability CVSS: 5.0 27 Jul 2017, 06:29 UTC

There is an illegal address access in the build_table function in libavcodec/bitstream.c of Libav 12.1 that will lead to remote denial of service via crafted input.

CVE-2017-9987 libav vulnerability CVSS: 5.0 28 Jun 2017, 06:29 UTC

There is a heap-based buffer overflow in the function hpel_motion in mpegvideo_motion.c in libav 12.1. A crafted input can lead to a remote denial of service attack.

CVE-2017-9051 libav vulnerability CVSS: 7.5 18 May 2017, 06:29 UTC

libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c.

CVE-2017-7208 libav vulnerability CVSS: 5.8 21 Mar 2017, 06:59 UTC

The decode_residual function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.

CVE-2017-7206 libav vulnerability CVSS: 5.8 21 Mar 2017, 06:59 UTC

The ff_h2645_extract_rbsp function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.

CVE-2016-9826 libav vulnerability CVSS: 4.3 01 Mar 2017, 15:59 UTC

libavcodec/ituh263dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

CVE-2016-9825 libav vulnerability CVSS: 4.3 01 Mar 2017, 15:59 UTC

libswscale/utils.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

CVE-2016-9824 libav vulnerability CVSS: 4.3 01 Mar 2017, 15:59 UTC

Integer overflow in libswscale/x86/swscale.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVE-2016-9823 libav vulnerability CVSS: 4.3 01 Mar 2017, 15:59 UTC

libavcodec/x86/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVE-2016-9822 libav vulnerability CVSS: 4.3 01 Mar 2017, 15:59 UTC

Integer overflow in libavcodec/mpeg12dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVE-2016-9821 libav vulnerability CVSS: 4.3 01 Mar 2017, 15:59 UTC

Integer overflow in libavcodec/mpegvideo_parser.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVE-2016-9820 libav vulnerability CVSS: 4.3 01 Mar 2017, 15:59 UTC

libavcodec/mpegvideo_motion.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

CVE-2016-9819 libav vulnerability CVSS: 4.3 01 Mar 2017, 15:59 UTC

libavcodec/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

CVE-2016-8676 libav vulnerability CVSS: 4.3 15 Feb 2017, 21:59 UTC

The get_vlc2 function in get_bits.h in Libav 11.9 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted mp3 file. NOTE: this issue exists due to an incomplete fix for CVE-2016-8675.

CVE-2016-8675 libav vulnerability CVSS: 4.3 15 Feb 2017, 21:59 UTC

The get_vlc2 function in get_bits.h in Libav before 11.9 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted mp3 file, possibly related to startcode sequences during m4v detection.

CVE-2016-7499 libav vulnerability CVSS: 4.3 15 Feb 2017, 21:59 UTC

The sbr_make_f_master function in aacsbr.c in Libav 11.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.

CVE-2016-7477 libav vulnerability CVSS: 4.3 15 Feb 2017, 21:59 UTC

The ff_put_pixels8_xy2_mmx function in rnd_template.c in Libav 11.7 allows remote attackers to cause a denial of service (invalid memory access and crash) via a crafted mp3 file. NOTE: this issue was originally reported as involving a NULL pointer dereference.

CVE-2016-7393 libav vulnerability CVSS: 4.3 15 Feb 2017, 21:59 UTC

Stack-based buffer overflow in the aac_sync function in aac_parser.c in Libav before 11.5 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

CVE-2016-6832 libav vulnerability CVSS: 4.3 15 Feb 2017, 19:59 UTC

Heap-based buffer overflow in the ff_audio_resample function in resample.c in libav before 11.4 allows remote attackers to cause a denial of service (crash) via vectors related to buffer resizing.

CVE-2016-7424 libav vulnerability CVSS: 4.3 07 Oct 2016, 14:59 UTC

The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file.

CVE-2016-3062 libav vulnerability CVSS: 6.8 16 Jun 2016, 18:59 UTC

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.

CVE-2015-5479 libav vulnerability CVSS: 4.3 19 Apr 2016, 14:59 UTC

The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.

CVE-2015-3395 libav vulnerability CVSS: 6.8 16 Jun 2015, 16:59 UTC

The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access.

CVE-2014-5271 libav vulnerability CVSS: 7.5 03 Nov 2014, 16:55 UTC

Heap-based buffer overflow in the encode_slice function in libavcodec/proresenc_kostya.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.x before 2.2.7, and 2.3.x before 2.3.3 and Libav before 10.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors.

CVE-2014-3984 libav vulnerability CVSS: 10.0 06 Jun 2014, 14:55 UTC

Multiple unspecified vulnerabilities in Libav before 0.8.12 allow remote attackers to have unknown impact and vectors.

CVE-2011-3937 libav vulnerability CVSS: 10.0 05 Jan 2013, 00:55 UTC

The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 has unspecified impact and attack vectors related to "width/height changing with frame threads."

CVE-2012-5144 libav vulnerability CVSS: 10.0 12 Dec 2012, 11:38 UTC

Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."

CVE-2012-2804 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors, related to "reallocation code" and the luma height and width.

CVE-2012-2803 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to resetting the data size value.

CVE-2012-2802 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the ac3_decode_frame function in libavcodec/ac3dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to the "number of output channels" and "out of array writes."

CVE-2012-2801 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to dimensions and "out of array writes."

CVE-2012-2800 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the ff_ivi_process_empty_tile function in libavcodec/ivi_common.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors in which the "tile size ... mismatches parameters" and triggers "writing into a too small array."

CVE-2012-2798 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array write."

CVE-2012-2797 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the decode_frame_mp3on4 function in libavcodec/mpegaudiodec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors related to a calculation that prevents a frame from being "large enough."

CVE-2012-2796 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the vc1_decode_frame function in libavcodec/vc1dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to inconsistencies in "coded slice positions and interlacing" that trigger "out of array writes."

CVE-2012-2794 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the decode_mb_info function in libavcodec/indeo5.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors in which the "allocated tile size ... mismatches parameters."

CVE-2012-2793 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the lag_decode_zero_run_line function in libavcodec/lagarith.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors related to "too many zeros."

CVE-2012-2791 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Multiple unspecified vulnerabilities in the (1) decode_band_hdr function in indeo4.c and (2) ff_ivi_decode_blocks function in ivi_common.c in libavcodec/ in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, have unknown impact and attack vectors, related to the "transform size."

CVE-2012-2790 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the read_var_block_data function in libavcodec/alsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to the "number of decoded samples in first sub-block in BGMC mode."

CVE-2012-2789 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to a large number of vector coded coefficients (num_vec_coeffs).

CVE-2012-2788 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array read" when a "packet is shrunk."

CVE-2012-2787 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the decode_frame function in libavcodec/indeo4.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to the "setup width/height."

CVE-2012-2786 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the decode_wdlt function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array write."

CVE-2012-2784 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to "width/height changing in CAVS," a different vulnerability than CVE-2012-2777.

CVE-2012-2783 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in libavcodec/vp56.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to "freeing the returned frame."

CVE-2012-2779 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the decode_frame function in libavcodec/indeo5.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an invalid "gop header" and decoding in a "half initialized context."

CVE-2012-2777 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to "width/height changing in CAVS," a different vulnerability than CVE-2012-2784.

CVE-2012-2776 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to an "out of picture write."

CVE-2012-2775 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the read_var_block_data function in libavcodec/alsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to a large order and an "out of array write in quant_cof."

CVE-2012-2772 libav vulnerability CVSS: 10.0 10 Sep 2012, 22:55 UTC

Unspecified vulnerability in the ff_rv34_decode_frame function in libavcodec/rv34.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to "width/height changing with frame threading."

CVE-2011-4579 libav vulnerability CVSS: 4.3 20 Aug 2012, 20:55 UTC

The svq1_decode_frame function in the SVQ1 decoder (svq1dec.c) in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (memory corruption) via a crafted SVQ1 stream, related to "dimensions changed."

CVE-2011-4364 libav vulnerability CVSS: 6.8 20 Aug 2012, 20:55 UTC

Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9 and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VMD file, related to corrupted streams.

CVE-2011-4353 libav vulnerability CVSS: 4.3 20 Aug 2012, 20:55 UTC

The (1) av_image_fill_pointers, (2) vp5_parse_coeff, and (3) vp6_parse_coeff functions in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted VP5 or VP6 stream.

CVE-2011-4352 libav vulnerability CVSS: 6.8 20 Aug 2012, 20:55 UTC

Integer overflow in the vp3_dequant function in the VP3 decoder (vp3.c) in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VP3 stream, which triggers a buffer overflow.

CVE-2011-3945 libav vulnerability CVSS: 6.8 20 Aug 2012, 20:55 UTC

The decode_frame function in the KVG1 decoder (kgv1dec.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted media file.

CVE-2012-0947 libav vulnerability CVSS: 6.8 20 Aug 2012, 18:55 UTC

Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo.c) in libavcodec in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VQA media file in which the image size is not a multiple of the block size.

CVE-2012-0858 libav vulnerability CVSS: 6.8 20 Aug 2012, 18:55 UTC

The Shorten codec (shorten.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Shorten file, related to an "invalid free".

CVE-2012-0853 libav vulnerability CVSS: 6.8 20 Aug 2012, 18:55 UTC

The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec in FFmpeg 0.7.x before 0.7.12, and 0.8.x before 0.8.11; and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (infinite loop and crash) and possibly execute arbitrary code via a large component count in an Atrac 3 file.

CVE-2012-0852 libav vulnerability CVSS: 6.8 20 Aug 2012, 18:55 UTC

The adpcm_decode_frame function in adpcm.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an ADPCM file with the number of channels not equal to two.

CVE-2012-0851 libav vulnerability CVSS: 6.8 20 Aug 2012, 18:55 UTC

The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted H.264 file, related to the chroma_format_idc value.

CVE-2011-3952 libav vulnerability CVSS: 6.8 20 Aug 2012, 18:55 UTC

The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large palette size in a KMVC encoded file.

CVE-2011-3951 libav vulnerability CVSS: 6.8 20 Aug 2012, 18:55 UTC

The dpcm_decode_frame function in dpcm.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted stereo stream in a media file.

CVE-2011-3947 libav vulnerability CVSS: 6.8 20 Aug 2012, 18:55 UTC

Buffer overflow in mjpegbdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MJPEG-B file.

CVE-2011-3940 libav vulnerability CVSS: 6.8 20 Aug 2012, 18:55 UTC

nsvdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted NSV file that triggers "use of uninitialized streams."

CVE-2011-3936 libav vulnerability CVSS: 4.3 20 Aug 2012, 18:55 UTC

The dv_extract_audio function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DV file.

CVE-2011-3929 libav vulnerability CVSS: 6.8 20 Aug 2012, 18:55 UTC

The avpriv_dv_produce_packet function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly execute arbitrary code via a crafted DV file.

CVE-2011-3362 libav vulnerability CVSS: 6.8 02 Oct 2011, 20:55 UTC

Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through 0.7.1, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.

CVE-2011-1931 libav vulnerability CVSS: 6.8 07 Jul 2011, 21:55 UTC

sp5xdec.c in the Sunplus SP5X JPEG decoder in libavcodec in FFmpeg before 0.6.3 and libav through 0.6.2, as used in VideoLAN VLC media player 1.1.9 and earlier and other products, performs a write operation outside the bounds of an unspecified array, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a malformed AMV file.