Lucene search

K
cvelistChromeCVELIST:CVE-2011-3952
HistoryAug 20, 2012 - 6:00 p.m.

CVE-2011-3952

2012-08-2018:00:00
Chrome
www.cve.org
6
decode_init function
kmvc.c
libavcodec
ffmpeg
libav
denial of service
execute arbitrary code
kmvc encoded file

AI Score

9.5

Confidence

High

EPSS

0.021

Percentile

89.3%

The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large palette size in a KMVC encoded file.

AI Score

9.5

Confidence

High

EPSS

0.021

Percentile

89.3%