VYPR

Ffmpeg

by FFmpeg

Source repositories

CVEs (525)

  • CVE-2023-39018CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no…

  • CVE-2017-16840CriNov 21, 2017
    risk 0.64cvss 9.8epss 0.03

    The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related to libavcodec/vc2enc.c and libavcodec/vc2enc_dwt.c.

  • CVE-2013-0870CriAug 28, 2017
    risk 0.64cvss 9.8epss 0.01

    The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.

  • CVE-2012-2781CriAug 9, 2017
    risk 0.64cvss 9.8epss 0.02

    Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2780.

  • CVE-2012-2780CriAug 9, 2017
    risk 0.64cvss 9.8epss 0.02

    Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2781.

  • CVE-2012-2778CriAug 9, 2017
    risk 0.64cvss 9.8epss 0.02

    Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2780, and CVE-2012-2781.

  • CVE-2012-2773CriAug 9, 2017
    risk 0.64cvss 9.8epss 0.02

    Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2781.

  • CVE-2012-2771CriAug 9, 2017
    risk 0.64cvss 9.8epss 0.02

    Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2773, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2781.

  • CVE-2017-7866CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.03

    FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c.

  • CVE-2017-7865CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.03

    FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c.

  • CVE-2017-7863CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.03

    FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.

  • CVE-2017-7862CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.03

    FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c.

  • CVE-2017-7859CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.02

    FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.

  • CVE-2016-6164CriJan 23, 2017
    risk 0.64cvss 9.8epss 0.02

    Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving sample size.

  • CVE-2014-4610HigJan 14, 2020
    risk 0.58cvss 8.8epss 0.04

    Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.

  • CVE-2016-3062HigJun 16, 2016
    risk 0.58cvss 8.8epss 0.04

    The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.

  • CVE-2026-66041HigJul 24, 2026
    risk 0.57cvss 8.8epss 0.00

    FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a…

  • CVE-2026-66040HigJul 24, 2026
    risk 0.57cvss 8.8epss 0.01

    FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf…

  • CVE-2026-66039HigJul 24, 2026
    risk 0.57cvss 8.8epss 0.00

    FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with…

  • CVE-2026-66036HigJul 24, 2026
    risk 0.57cvss 8.8epss 0.00

    FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is…

Page 1 of 27