libav 12.3

CPE Details

libav 12.3
12.3
2019-07-03
14h09 +00:00
2019-07-03
14h09 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:libav:libav:12.3:*:*:*:*:*:*:*

Informations

Vendor

libav

Product

libav

Version

12.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-8586 2025-08-05 17h32 +00:00 A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_frame_binary of the file /libavformat/utils.c of the component MPEG File Parser. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The bug was initially reported by the researcher to the wrong project. This vulnerability only affects products that are no longer supported by the maintainer.
4.8
Medium
CVE-2025-8585 2025-08-05 17h02 +00:00 A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The bug was initially reported by the researcher to the wrong project. This vulnerability only affects products that are no longer supported by the maintainer.
4.8
Medium
CVE-2025-8584 2025-08-05 16h32 +00:00 A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function av_buffer_unref of the file libavutil/buffer.c of the component AVI File Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The bug was initially reported by the researcher to the wrong project. This vulnerability only affects products that are no longer supported by the maintainer.
4.8
Medium
CVE-2020-18776 2021-08-23 19h50 +00:00 In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
6.5
Medium
CVE-2020-18778 2021-08-23 19h50 +00:00 In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
6.5
Medium
CVE-2020-18775 2021-08-23 19h50 +00:00 In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
6.5
Medium
CVE-2019-9720 2019-09-19 18h37 +00:00 A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.
6.5
Medium
CVE-2019-9719 2019-09-19 18h32 +00:00 A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf. NOTE: Third parties dispute that this is a vulnerability because “no evidence of a vulnerability is provided” and only “a generic warning from a static code analysis” is provided
8.8
High
CVE-2019-9717 2019-09-19 18h28 +00:00 In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex format argument to sscanf.
6.5
Medium
CVE-2019-14443 2019-07-30 10h05 +00:00 An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.
6.5
Medium
CVE-2019-14442 2019-07-30 10h05 +00:00 In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to cause a denial of service via a crafted file.
6.5
Medium
CVE-2019-14441 2019-07-30 10h05 +00:00 An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ff_mpa_synth_filter_float in avcodec/mpegaudiodsp_template.c. NOTE: This may be a duplicate of CVE-2018-19129
6.5
Medium
CVE-2019-14372 2019-07-28 16h44 +00:00 In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.
6.5
Medium
CVE-2019-14371 2019-07-28 16h44 +00:00 An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.
6.5
Medium
CVE-2018-20001 2018-12-10 02h00 +00:00 In Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits) in libavcodec/apedec.c that will lead to remote denial of service via crafted input.
6.5
Medium
CVE-2018-19128 2018-11-09 10h00 +00:00 In Libav 12.3, there is a heap-based buffer over-read in decode_frame in libavcodec/lcldec.c that allows an attacker to cause denial-of-service via a crafted avi file.
6.5
Medium
CVE-2018-19129 2018-11-09 10h00 +00:00 In Libav 12.3, a NULL pointer dereference (RIP points to zero) issue in ff_mpa_synth_filter_float in libavcodec/mpegaudiodsp_template.c can cause a segmentation fault (application crash) via a crafted mov file.
6.5
Medium
CVE-2018-19130 2018-11-09 10h00 +00:00 In Libav 12.3, there is an invalid memory access in vc1_decode_frame in libavcodec/vc1dec.c that allows attackers to cause a denial-of-service via a crafted aac file. NOTE: This may be a duplicate of CVE-2017-17127
6.5
Medium
CVE-2018-18826 2018-10-30 05h00 +00:00 There exists a heap-based buffer overflow in vc1_decode_p_mb_intfi in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
6.5
Medium
CVE-2018-18827 2018-10-30 05h00 +00:00 There exists a heap-based buffer over-read in ff_vc1_pred_dc in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
6.5
Medium
CVE-2018-18828 2018-10-30 05h00 +00:00 There exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
6.5
Medium
CVE-2018-18829 2018-10-30 05h00 +00:00 There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers to cause a denial-of-service through a crafted aac file.
6.5
Medium
CVE-2018-11224 2018-05-17 04h00 +00:00 An issue was discovered in Libav 12.3. A read access violation in the in_table_init16 function in libavcodec/aacsbr.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.
6.5
Medium
CVE-2018-11102 2018-05-15 00h00 +00:00 An issue was discovered in Libav 12.3. A read access violation in the mov_probe function in libavformat/mov.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.
7.5
High