cbcvebase.
CVE-2016-5199
published 2017-01-19

CVE-2016-5199: An off by one error resulting in an allocation of zero size in FFmpeg in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and…

PriorityP338high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.37%
69.0th percentile
An off by one error resulting in an allocation of zero size in FFmpeg in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted video file.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianffmpeg< ffmpeg 7:3.2-1 (bookworm)ffmpeg 7:3.2-1 (bookworm)
ffmpegffmpeg>= 0 < 7:3.2-17:3.2-1
ffmpegffmpeg>= 0 < 7:3.2-17:3.2-1
ffmpegffmpeg>= 0 < 7:3.2-17:3.2-1
ffmpegffmpeg>= 0 < 7:3.2-17:3.2-1
googlechrome<= 54.0.2840.87

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.