VYPR

rpm package

opensuse/ffmpeg-8&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/ffmpeg-8&distro=openSUSE%20Tumbleweed

Vulnerabilities (6)

  • CVE-2026-12706MedJun 19, 2026
    affected < 8.1.2-2.1fixed 8.1.2-2.1

    A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed buffer, but a subsequent reallocation of that same buffer during move-table processing leaves the pointer dangling. An attacker could

  • CVE-2026-8461HigJun 18, 2026
    affected < 8.1.2-2.1fixed 8.1.2-2.1

    An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issu

  • CVE-2026-30997HigApr 13, 2026
    affected < 8.1.1-3.1fixed 8.1.1-3.1

    An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-10256MedFeb 18, 2026
    affected < 8.1.1-3.1fixed 8.1.1-3.1

    A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a cr

  • CVE-2025-9951HigSep 9, 2025
    affected < 8.1.1-3.1fixed 8.1.1-3.1

    A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.

  • CVE-2025-1594MedFeb 23, 2025
    affected < 8.1.1-3.1fixed 8.1.1-3.1

    A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate th