Faad2 Project Faad2 vulnerabilities

39 known vulnerabilities affecting faad2_project/faad2.

Total CVEs
39
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH14MEDIUM23

Vulnerabilities

Page 1 of 2
CVE-2023-38858MEDIUMCVSS 6.5v2.10.12023-08-15
CVE-2023-38858 [MEDIUM] CWE-787 CVE-2023-38858: Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code an Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the mp4info function in mp4read.c:1039.
nvdosv
CVE-2023-38857MEDIUMCVSS 5.5v2.10.12023-08-15
CVE-2023-38857 [MEDIUM] CWE-787 CVE-2023-38857: Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code an Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the stcoin function in mp4read.c.
nvdosv
CVE-2021-32277HIGHCVSS 7.8≤ 2.10.02021-09-20
CVE-2021-32277 [HIGH] CWE-787 CVE-2021-32277: An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_q An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c. It allows an attacker to cause code Execution.
nvdosv
CVE-2021-32273HIGHCVSS 7.8≤ 2.10.02021-09-20
CVE-2021-32273 [HIGH] CWE-787 CVE-2021-32273: An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftyp An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an attacker to cause Code Execution.
nvdosv
CVE-2021-32274HIGHCVSS 7.8≤ 2.10.02021-09-20
CVE-2021-32274 [HIGH] CWE-787 CVE-2021-32274: An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_q An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c. It allows an attacker to cause code Execution.
nvdosv
CVE-2021-32272HIGHCVSS 7.8fixed in 2.10.02021-09-20
CVE-2021-32272 [HIGH] CWE-787 CVE-2021-32272: An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.
nvdosv
CVE-2021-32278HIGHCVSS 7.8≤ 2.10.02021-09-20
CVE-2021-32278 [HIGH] CWE-787 CVE-2021-32278: An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_pr An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an attacker to cause code Execution.
nvdosv
CVE-2021-32276MEDIUMCVSS 5.5≤ 2.10.02021-09-20
CVE-2021-32276 [MEDIUM] CWE-476 CVE-2021-32276: An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function g An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an attacker to cause Denial of Service.
nvdosv
CVE-2021-26567HIGHCVSS 7.8fixed in 2.2.7.12021-02-26
CVE-2021-26567 [HIGH] CWE-121 CVE-2021-26567: Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local att Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options.
nvd
CVE-2019-15296HIGHCVSS 7.8≥ 0, < 2.8.8-32019-08-21
CVE-2019-15296 [HIGH] CVE-2019-15296: An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2 An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The faad_resetbits function in libfaad/bits.c is affected by a buffer overflow vulnerability. The number of bits to be read is determined by ld->buffer_size - words*4, cast to uint32. If ld->buffer_size - words*4 is negative, a buffer overflow is later performed via getdword_n(&ld->start[words], ld->bytes_left).
osv
CVE-2019-6956HIGHCVSS 7.1≥ 0, < 2.8.8-3.12019-01-25
CVE-2019-6956 [HIGH] CVE-2019-6956: An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2 An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.
osv
CVE-2018-20362MEDIUMCVSS 5.5≥ 0, < 2.8.8-22018-12-22
CVE-2018-20362 [MEDIUM] CVE-2018-20362: A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash because adding to windowed output is mishandled in the EIGHT_SHORT_SEQUENCE case.
osv
CVE-2018-20361MEDIUMCVSS 5.5≥ 0, < 2.8.8-22018-12-22
CVE-2018-20361 [MEDIUM] CVE-2018-20361: An invalid memory address dereference was discovered in the hf_assembly function of libfaad/sbr_hfadj An invalid memory address dereference was discovered in the hf_assembly function of libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
osv
CVE-2018-20357MEDIUMCVSS 5.5≥ 0, < 2.8.8-22018-12-22
CVE-2018-20357 [MEDIUM] CVE-2018-20357: A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash.
osv
CVE-2018-20360MEDIUMCVSS 5.5≥ 0, < 2.8.8-3.12018-12-22
CVE-2018-20360 [MEDIUM] CVE-2018-20360: An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
osv
CVE-2018-20358MEDIUMCVSS 5.5≥ 0, < 2.8.8-22018-12-22
CVE-2018-20358 [MEDIUM] CVE-2018-20358: An invalid memory address dereference was discovered in the lt_prediction function of libfaad/lt_predict An invalid memory address dereference was discovered in the lt_prediction function of libfaad/lt_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
osv
CVE-2018-20359MEDIUMCVSS 5.5≥ 0, < 2.8.8-22018-12-22
CVE-2018-20359 [MEDIUM] CVE-2018-20359: An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
osv
CVE-2018-20197HIGHCVSS 7.8≥ 0, < 2.8.8-22018-12-18
CVE-2018-20197 [HIGH] CVE-2018-20197: There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled for the G_max > G case.
osv
CVE-2018-20196HIGHCVSS 7.8≥ 0, < 2.8.8-3.12018-12-18
CVE-2018-20196 [HIGH] CVE-2018-20196: There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled.
osv
CVE-2018-20194HIGHCVSS 7.8≥ 0, < 2.8.8-22018-12-18
CVE-2018-20194 [HIGH] CVE-2018-20194: There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled for the G_max <= G case.
osv