Loading
In Libav 12.3, there is a heap-based buffer over-read in decode_frame in libavcodec/lcldec.c that allows an attacker to cause denial-of-service via a crafted avi file.
Cite this page
CVE-2018-19128. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2018-19128
Use CWE-125, Libav vendor hub and Libav product page to widen CVE-2018-19128 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-4609, CVE-2019-9719 and CVE-2020-18778 for nearby disclosures in the same product family.