cbcvebase.

Debian Faad2 vulnerabilities

36 known vulnerabilities affecting debian/faad2.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH11MEDIUM1LOW23

Vulnerabilities

Page 1 of 2
CVE-2008-4201P3CRITICALCVSS 9.3fixed in faad2 2.6.1-3.1 (bookworm)2008
CVE-2008-4201 [CRITICAL] CVE-2008-4201: faad2 - Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FA... Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file. Scope: local bookworm: resolved (fixed in 2.6.1-3.1) bullseye: resolved (fixed in 2.6.1-3.1) forky: resolved (fixed in 2.6.1-3.1) sid: r
debian
CVE-2021-32278P3HIGHCVSS 7.8fixed in faad2 2.10.0-1 (bookworm)2021
CVE-2021-32278 [HIGH] CVE-2021-32278: faad2 - An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists i... An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an attacker to cause code Execution. Scope: local bookworm: resolved (fixed in 2.10.0-1) bullseye: resolved (fixed in 2.10.0-1) forky: resolved (fixed in 2.10.0-1) sid: resolved (fixed in 2.10.0-1) trixie: resolved (fixed in 2
debian
CVE-2021-32274P3HIGHCVSS 7.8fixed in faad2 2.10.0-1 (bookworm)2021
CVE-2021-32274 [HIGH] CVE-2021-32274: faad2 - An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists i... An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c. It allows an attacker to cause code Execution. Scope: local bookworm: resolved (fixed in 2.10.0-1) bullseye: resolved (fixed in 2.10.0-1) forky: resolved (fixed in 2.10.0-1) sid: resolved (fixed in 2.10.0-1) trixie: resolved (fixed
debian
CVE-2021-32277P3HIGHCVSS 7.8fixed in faad2 2.10.0-1 (bookworm)2021
CVE-2021-32277 [HIGH] CVE-2021-32277: faad2 - An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists i... An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c. It allows an attacker to cause code Execution. Scope: local bookworm: resolved (fixed in 2.10.0-1) bullseye: resolved (fixed in 2.10.0-1) forky: resolved (fixed in 2.10.0-1) sid: resolved (fixed in 2.10.0-1) trixie: resolved (fixed i
debian
CVE-2021-32272P3HIGHCVSS 7.8fixed in faad2 2.10.0-1 (bookworm)2021
CVE-2021-32272 [HIGH] CVE-2021-32272: faad2 - An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in... An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution. Scope: local bookworm: resolved (fixed in 2.10.0-1) bullseye: resolved (fixed in 2.10.0-1) forky: resolved (fixed in 2.10.0-1) sid: resolved (fixed in 2.10.0-1) trixie: resolved (fixed in 2.10.0-1)
debian
CVE-2018-19502P4HIGHCVSS 7.8fixed in faad2 2.8.8-3 (bookworm)2018
CVE-2018-19502 [HIGH] CVE-2018-19502: faad2 - An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. Ther... An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c. Scope: local bookworm: resolved (fixed in 2.8.8-3) bullseye: resolved (fixed in 2.8.8-3) forky: resolved (fixed in 2.8.8-3) sid: resolved (fixed in 2.8.8-3) trixie: resolved (fixed in 2.8.8-3)
debian
CVE-2018-19503P4HIGHCVSS 7.8fixed in faad2 2.8.8-2 (bookworm)2018
CVE-2018-19503 [HIGH] CVE-2018-19503: faad2 - An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. Ther... An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a stack-based buffer overflow in the function calculate_gain() in libfaad/sbr_hfadj.c. Scope: local bookworm: resolved (fixed in 2.8.8-2) bullseye: resolved (fixed in 2.8.8-2) forky: resolved (fixed in 2.8.8-2) sid: resolved (fixed in 2.8.8-2) trixie: resolved (fixed in 2.8.8-2)
debian
CVE-2019-15296P4HIGHCVSS 7.8fixed in faad2 2.8.8-3 (bookworm)2019
CVE-2019-15296 [HIGH] CVE-2019-15296: faad2 - An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The ... An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The faad_resetbits function in libfaad/bits.c is affected by a buffer overflow vulnerability. The number of bits to be read is determined by ld->buffer_size - words*4, cast to uint32. If ld->buffer_size - words*4 is negative, a buffer overflow is later performed via getdword_n(&ld->start[words
debian
CVE-2018-20194P4HIGHCVSS 7.8fixed in faad2 2.8.8-2 (bookworm)2018
CVE-2018-20194 [HIGH] CVE-2018-20194: faad2 - There is a stack-based buffer underflow in the third instance of the calculate_g... There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled for the G_max <= G case. Scope: local bookworm: res
debian
CVE-2018-20197P4HIGHCVSS 7.8fixed in faad2 2.8.8-2 (bookworm)2018
CVE-2018-20197 [HIGH] CVE-2018-20197: faad2 - There is a stack-based buffer underflow in the third instance of the calculate_g... There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled for the G_max > G case. Scope: local bookworm: reso
debian
CVE-2021-32273P4HIGHCVSS 7.8fixed in faad2 2.10.0-1 (bookworm)2021
CVE-2021-32273 [HIGH] CVE-2021-32273: faad2 - An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists ... An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an attacker to cause Code Execution. Scope: local bookworm: resolved (fixed in 2.10.0-1) bullseye: resolved (fixed in 2.10.0-1) forky: resolved (fixed in 2.10.0-1) sid: resolved (fixed in 2.10.0-1) trixie: resolved (fixed in 2.10.0-1)
debian
CVE-2008-5244P4LOWCVSS 10.0fixed in faad2 2.6.1-1 (bookworm)2008
CVE-2008-5244 [CRITICAL] CVE-2008-5244: faad2 - Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attac... Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad. NOTE: due to the lack of details, it is not clear whether this is an issue in xine-lib or in libfaad. Scope: local bookworm: resolved (fixed in 2.6.1-1) bullseye: resolved (fixed in 2.6.1-1) forky: resolved (fixed in 2.6.1-1) sid: resolved (fixed in 2.6.1-1)
debian
CVE-2018-20196P4LOWCVSS 7.8fixed in faad2 2.8.8-3.1 (bookworm)2018
CVE-2018-20196 [HIGH] CVE-2018-20196: faad2 - There is a stack-based buffer overflow in the third instance of the calculate_ga... There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled. Scope: local bookworm: resolved (fixed in 2.8.8-3.1) bullseye: resolved (fixed i
debian
CVE-2018-19504P4LOWCVSS 7.8fixed in faad2 2.8.8-2 (bookworm)2018
CVE-2018-19504 [HIGH] CVE-2018-19504: faad2 - An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. Ther... An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There is a NULL pointer dereference in ifilter_bank() in libfaad/filtbank.c. Scope: local bookworm: resolved (fixed in 2.8.8-2) bullseye: resolved (fixed in 2.8.8-2) forky: resolved (fixed in 2.8.8-2) sid: resolved (fixed in 2.8.8-2) trixie: resolved (fixed in 2.8.8-2)
debian
CVE-2019-6956P4HIGHCVSS 7.1fixed in faad2 2.8.8-3.1 (bookworm)2019
CVE-2019-6956 [HIGH] CVE-2019-6956: faad2 - An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It i... An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c. Scope: local bookworm: resolved (fixed in 2.8.8-3.1) bullseye: resolved (fixed in 2.8.8-3.1) forky: resolved (fixed in 2.8.8-3.1) sid: resolved (fixed in 2.8.8-3.1) trixie: resolved (fixed in 2.8.8-3.1)
debian
CVE-2017-9220P4LOWCVSS 5.5fixed in faad2 2.8.1-1 (bookworm)2017
CVE-2017-9220 [MEDIUM] CVE-2017-9220: faad2 - The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audi... The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error) via a crafted mp4 file. Scope: local bookworm: resolved (fixed in 2.8.1-1) bullseye: resolved (fixed in 2.8.1-1) forky: resolved (fixed in 2.8.1-1) sid: resolved (fixed in 2.8.1-1) trixie
debian
CVE-2018-20198P4LOWCVSS 5.5fixed in faad2 2.8.8-2 (bookworm)2018
CVE-2018-20198 [MEDIUM] CVE-2018-20198: faad2 - A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c ... A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service because adding to windowed output is mishandled in the LONG_START_SEQUENCE case. Scope: local bookworm: resolved (fixed in 2.8.8-2) bu
debian
CVE-2018-20361P4LOWCVSS 5.5fixed in faad2 2.8.8-2 (bookworm)2018
CVE-2018-20361 [MEDIUM] CVE-2018-20361: faad2 - An invalid memory address dereference was discovered in the hf_assembly function... An invalid memory address dereference was discovered in the hf_assembly function of libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. Scope: local bookworm: resolved (fixed in 2.8.8-2) bullseye: resolved (fixed in 2.8.8-2) forky: resolved (fix
debian
CVE-2021-32276P4MEDIUMCVSS 5.5fixed in faad2 2.10.0-1 (bookworm)2021
CVE-2021-32276 [MEDIUM] CVE-2021-32276: faad2 - An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exis... An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an attacker to cause Denial of Service. Scope: local bookworm: resolved (fixed in 2.10.0-1) bullseye: resolved (fixed in 2.10.0-1) forky: resolved (fixed in 2.10.0-1) sid: resolved (fixed in 2.10.0-1) trixie: resolved (fixed
debian
CVE-2017-9253P4LOWCVSS 5.5fixed in faad2 2.8.1-1 (bookworm)2017
CVE-2017-9253 [MEDIUM] CVE-2017-9253: faad2 - The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audi... The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file. Scope: local bookworm: resolved (fixed in 2.8.1-1) bullseye: resolved (fixed in 2.8.1-1) forky: resolved (fixed in 2.8.1-1) sid: resolved (fixed in 2.8.1-1)
debian
Debian Faad2 vulnerabilities | cvebase