Search CVE reports


Toggle filters

61 – 70 of 156 results


CVE-2018-11529

Medium priority

Some fixes available 2 of 3

VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — Not affected Not affected Not affected
Show less packages

CVE-2018-13305

Medium priority
Needs evaluation

In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function in libavcodec/vc1_block.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4,...

7 affected packages

mythtv, gst-libav1.0, chromium-browser, ffmpeg, libav...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release Not in release
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages

CVE-2018-13304

Medium priority
Needs evaluation

In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger an assertion failure while converting a crafted AVI file to MPEG4, leading to a...

12 affected packages

dvbcut, mythtv, gst-libav1.0, kino, chromium-browser...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dvbcut Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kino Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release Not in release
libav Not in release Not in release Not in release Not in release Not in release
mplayer Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
xine-lib Not in release Not in release Not in release Not in release Not in release
Show all 12 packages Show less packages

CVE-2018-13303

Low priority
Needs evaluation

In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in libavcodec/ac3_parser.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4,...

10 affected packages

mythtv, gst-libav1.0, kino, chromium-browser, ffmpeg...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kino Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release Not in release
libav Not in release Not in release Not in release Not in release Not in release
mplayer Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show all 10 packages Show less packages

CVE-2018-13302

Medium priority

Some fixes available 18 of 89

In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independent substreams in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array access while...

10 affected packages

mythtv, gst-libav1.0, kino, chromium-browser, ffmpeg...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kino Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Fixed Fixed Fixed Fixed Fixed
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release Not in release
libav Not in release Not in release Not in release Not in release Not in release
mplayer Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show all 10 packages Show less packages

CVE-2018-13301

Low priority
Needs evaluation

In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c may trigger a NULL pointer dereference while converting a crafted AVI file to...

9 affected packages

mythtv, gst-libav1.0, chromium-browser, ffmpeg, gstreamer0.10-ffmpeg...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected Not affected
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release Not in release
libav Not in release Not in release Not in release Not in release Not in release
mplayer Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show all 9 packages Show less packages

CVE-2018-13300

Medium priority

Some fixes available 17 of 88

In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array read while converting a crafted AVI...

10 affected packages

mythtv, gst-libav1.0, kino, chromium-browser, ffmpeg...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kino Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
chromium-browser Ignored Ignored Ignored Not in release Ignored
ffmpeg Fixed Fixed Fixed Fixed Fixed
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release Not in release
libav Not in release Not in release Not in release Not in release Not in release
mplayer Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show all 10 packages Show less packages

CVE-2018-11516

Medium priority
Ignored

The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified...

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — — — Not affected
Show less packages

CVE-2018-7751

Medium priority

Some fixes available 1 of 43

The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file.

7 affected packages

mythtv, gst-libav1.0, ffmpeg, libav, mplayer...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Not affected Fixed
libav Not in release Not in release Not in release Not in release Not in release
mplayer Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages

CVE-2015-1208

Medium priority
Ignored

Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.

4 affected packages

ffmpeg, libav, mplayer, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg — — — — Not affected
libav — — — — Not in release
mplayer — — — — Not affected
vlc — — — — Not affected
Show less packages