VYPR

rpm package

opensuse/ffmpeg-7&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Tumbleweed

Vulnerabilities (69)

  • CVE-2026-65703HigJul 23, 2026
    affected < 7.1.5-2.1fixed 7.1.5-2.1

    FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to

  • CVE-2026-64835HigJul 22, 2026
    affected < 7.1.5-2.1fixed 7.1.5-2.1

    FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel l

  • CVE-2026-64834HigJul 22, 2026
    affected < 7.1.5-2.1fixed 7.1.5-2.1

    FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minim

  • CVE-2026-64833HigJul 22, 2026
    affected < 7.1.5-2.1fixed 7.1.5-2.1

    FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit

  • CVE-2026-64832HigJul 22, 2026
    affected < 7.1.5-2.1fixed 7.1.5-2.1

    FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep

  • CVE-2026-64830HigJul 22, 2026
    affected < 7.1.5-2.1fixed 7.1.5-2.1

    FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bound

  • CVE-2026-58049HigJun 28, 2026
    affected < 7.1.5-2.1fixed 7.1.5-2.1

    FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the

  • CVE-2026-12706MedJun 19, 2026
    affected < 7.1.4-5.1fixed 7.1.4-5.1

    A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed buffer, but a subsequent reallocation of that same buffer during move-table processing leaves the pointer dangling. An attacker could

  • CVE-2026-8461HigJun 18, 2026
    affected < 7.1.5-1.1fixed 7.1.5-1.1

    An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issu

  • CVE-2026-40962MedApr 16, 2026
    affected < 7.1.3-3.1fixed 7.1.3-3.1

    FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

  • CVE-2026-30997HigApr 13, 2026
    affected < 7.1.4-3.1fixed 7.1.4-3.1

    An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-10256MedFeb 18, 2026
    affected < 7.1.4-2.1fixed 7.1.4-2.1

    A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a cr

  • CVE-2025-7700MedNov 7, 2025
    affected < 7.1.1-8.1fixed 7.1.1-8.1

    A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrup

  • CVE-2025-9951HigSep 9, 2025
    affected < 7.1.4-2.1fixed 7.1.4-2.1

    A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.

  • CVE-2025-1816MedMar 2, 2025
    affected < 7.1.1-1.1fixed 7.1.1-1.1

    A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This affects the function audio_element_obu of the file libavformat/iamf_parse.c of the component IAMF File Handler. The manipulation of the argument num_parameters

  • CVE-2025-1594MedFeb 23, 2025
    affected < 7.1.4-2.1fixed 7.1.4-2.1

    A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate th

  • CVE-2025-25473MedFeb 18, 2025
    affected < 7.1-3.1fixed 7.1-3.1

    FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.

  • CVE-2025-22920MedFeb 18, 2025
    affected < 7.1-3.1fixed 7.1-3.1

    A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).

  • CVE-2025-22919MedFeb 18, 2025
    affected < 7.1-3.1fixed 7.1-3.1

    A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.

  • CVE-2025-22921MedFeb 18, 2025
    affected < 7.1-3.1fixed 7.1-3.1

    FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.