Search CVE reports


Toggle filters

51 – 60 of 156 results


CVE-2019-5439

Medium priority

Some fixes available 2 of 4

A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-19857

Medium priority

Some fixes available 1 of 3

The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to...

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-18829

Medium priority
Needs evaluation

There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers to cause a denial-of-service through a crafted aac file.

5 affected packages

qtwebengine-opensource-src, gst-libav1.0, ffmpeg, libav, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18828

Medium priority
Needs evaluation

There exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

5 affected packages

qtwebengine-opensource-src, gst-libav1.0, ffmpeg, libav, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18827

Medium priority
Needs evaluation

There exists a heap-based buffer over-read in ff_vc1_pred_dc in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

5 affected packages

qtwebengine-opensource-src, gst-libav1.0, ffmpeg, libav, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18826

Medium priority
Needs evaluation

There exists a heap-based buffer overflow in vc1_decode_p_mb_intfi in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

5 affected packages

qtwebengine-opensource-src, gst-libav1.0, ffmpeg, libav, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-1999014

Medium priority
Needs evaluation

FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which...

7 affected packages

gst-libav1.0, qtwebengine-opensource-src, kino, chromium-browser, ffmpeg...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kino Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages

CVE-2018-1999012

Medium priority

Some fixes available 1 of 65

FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in a Vulnerability that allows attackers to consume excessive amount of resources...

8 affected packages

gst-libav1.0, qtwebengine-opensource-src, kino, chromium-browser, ffmpeg...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kino Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release Not in release
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show all 8 packages Show less packages

CVE-2018-1999011

Medium priority
Needs evaluation

FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow vulnerability in asf_o format demuxer that can result in heap-buffer-overflow that may result in remote code execution. This attack appears...

6 affected packages

qtwebengine-opensource-src, gst-libav1.0, chromium-browser, ffmpeg, oxide-qt, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-1999010

Medium priority

Some fixes available 1 of 55

FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable...

7 affected packages

qtwebengine-opensource-src, gst-libav1.0, chromium-browser, ffmpeg, libav...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release Not in release
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages