CVE-2015-3417

FFmpeg <2.3.6 - Use After Free

Title source: llm

Description

Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.

Scores

EPSS 0.0102
EPSS Percentile 76.9%

Classification

Status draft

Affected Products (2)

ffmpeg/ffmpeg < 2.3.5
debian/debian_linux

Timeline

Published Apr 24, 2015
Tracked Since Feb 18, 2026