📦

faad2

Vendor: audiocoding

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 6 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 1.66% Exploit Prob.
Latest CVE CVE-2023-38858 Aug 15

Security Vulnerability Index

Page 1 / 1
6.5 CVSS

Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the mp4info function in mp4read.c:1039.

EPSS: 0.90%
5.5 CVSS

Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the stcoin function in mp4read.c.

EPSS: 0.52%
7.8 CVSS

An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an attacker to cause code Execution.

EPSS: 1.32%
7.8 CVSS

An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c. It allows an attacker to cause code Execution.

EPSS: 1.31%
5.5 CVSS

An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an attacker to cause Denial of Service.

EPSS: 0.96%
7.8 CVSS

An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c. It allows an attacker to cause code Execution.

EPSS: 1.32%
7.8 CVSS

An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an attacker to cause Code Execution.

EPSS: 1.17%
7.8 CVSS

An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.

EPSS: 1.31%
7.8 CVSS

Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options.

EPSS: 1.13%
9.3 CVSS

Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file.

EPSS: 6.65%