Show plain JSON{"id": "CVE-2014-9316", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2014-12-09T23:59:14.067", "references": [{"url": "http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=0eecf40935b22644e6cd74c586057237ecfd6844", "source": "cve@mitre.org"}, {"url": "https://security.gentoo.org/glsa/201603-06", "source": "cve@mitre.org"}, {"url": "https://www.ffmpeg.org/security.html", "source": "cve@mitre.org"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-119"}]}], "descriptions": [{"lang": "en", "value": "The mjpeg_decode_app function in libavcodec/mjpegdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via vectors related to LJIF tags in an MJPEG file."}, {"lang": "es", "value": "La funci\u00f3n mjpeg_decode_app en libavcodec/mjpegdec.c en FFMpeg anterior a 2.1.6, 2.2.x hasta 2.3.x, y 2.4.x anterior a 2.4.4 permite a atacantes remotos causar una denegaci\u00f3n de servicio (acceso a memoria din\u00e1mica fuera de rango) y posiblemente tener otro impacto no especificado a trav\u00e9s de vectores relacionados con las etiquetas LJIF en un fichero MJPEG."}], "lastModified": "2023-11-07T02:23:03.690", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5DD2B585-5D64-46DE-ACB0-214E146A3C48", "versionEndIncluding": "2.1.5"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B08A7BE-7C98-4659-808F-86A8EB4676D2"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CE9CF7C7-3730-43EC-B63E-B004D979E57A"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "207DF654-326E-43A9-A5EC-BC239BF30422"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B50AB2A-FA23-4BB0-AA21-724E770ADEFB"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "94BC4C82-371C-4B80-A615-AE0F15F1D6CA"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0E114D7-1323-4965-9680-8638ACDFF20B"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7BBF39F-668E-4771-99A0-F008B18B03F5"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C3E41754-D2AB-4DE1-9ED9-A88F5E28ABFF"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14D1738D-D85A-4650-9DAB-C626E7F52812"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A91B8DD5-FB80-47E7-8AF3-57D72CD4D034"}, {"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1ADB969-FA62-4238-83DF-D5703603A9FE"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}