VYPR

Ffmpeg

by FFmpeg

Source repositories

CVEs (525)

  • CVE-2025-10256MedFeb 18, 2026
    risk 0.00cvss 5.3epss 0.00

    A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a…

  • CVE-2025-0518MedJan 16, 2025
    risk 0.00cvss 5.3epss 0.00

    Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C . This issue affects FFmpeg: 7.1. …

  • CVE-2024-36613MedJan 3, 2025
    risk 0.00cvss 6.2epss 0.00

    FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.

  • CVE-2024-35365HigJan 3, 2025
    risk 0.00cvss 8.8epss 0.01

    FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.

  • CVE-2024-35368CriNov 29, 2024
    risk 0.00cvss 9.8epss 0.01

    FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.

  • CVE-2024-35367CriNov 29, 2024
    risk 0.00cvss 9.1epss 0.01

    FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer

  • CVE-2024-35366CriNov 29, 2024
    risk 0.00cvss 9.1epss 0.01

    FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without…

  • CVE-2024-36616MedNov 29, 2024
    risk 0.00cvss 6.5epss 0.01

    An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.

  • CVE-2024-36615MedNov 29, 2024
    risk 0.00cvss 5.9epss 0.00

    FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.

  • CVE-2024-36618MedNov 29, 2024
    risk 0.00cvss 6.2epss 0.00

    FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.

  • CVE-2024-36617MedNov 29, 2024
    risk 0.00cvss 6.2epss 0.00

    FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.

  • CVE-2024-36619MedNov 29, 2024
    risk 0.00cvss 5.3epss 0.01

    FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.

  • CVE-2024-35369MedNov 29, 2024
    risk 0.00cvss 5.5epss 0.00

    In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions,…

  • CVE-2023-50010HigApr 19, 2024
    risk 0.00cvss 7.8epss 0.00

    FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component.

  • CVE-2023-50009HigApr 19, 2024
    risk 0.00cvss 8.0epss 0.00

    FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.

  • CVE-2023-50008HigApr 19, 2024
    risk 0.00cvss 7.8epss 0.00

    FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.

  • CVE-2023-50007MedApr 19, 2024
    risk 0.00cvss 4.0epss 0.00

    FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.

  • CVE-2024-31585MedApr 17, 2024
    risk 0.00cvss 5.3epss 0.00

    FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-31582HigApr 17, 2024
    risk 0.00cvss 7.8epss 0.00

    FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input.

  • CVE-2024-31581CriApr 17, 2024
    risk 0.00cvss 9.8epss 0.01

    FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within the application.

Page 14 of 27