VYPR

Ffmpeg

by FFmpeg

Source repositories

CVEs (548)

  • CVE-2018-14394MedJul 19, 2018
    risk 0.35cvss 6.5epss 0.01

    libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted Waveform audio file.

  • CVE-2025-7700MedNov 7, 2025
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to…

  • CVE-2024-55069MedMay 2, 2025
    risk 0.34cvss 5.3epss 0.00

    ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.

  • CVE-2023-6604MedJan 6, 2025
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.

  • CVE-2023-6602MedDec 31, 2024
    risk 0.34cvss 5.3epss 0.01

    A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.

  • CVE-2014-125018MedJun 19, 2022
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in FFmpeg 2.0. Affected by this issue is the function decode_slice_header. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.

  • CVE-2014-125011MedJun 18, 2022
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in FFmpeg 2.0. It has been declared as problematic. Affected by this vulnerability is the function decode_frame of the file libavcodec/ansi.c. The manipulation leads to integer coercion error. The attack can be launched remotely. It is recommended to…

  • CVE-2014-125010MedJun 18, 2022
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function decode_slice_header of the file libavcodec/h64.c. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch…

  • CVE-2026-40962MedApr 16, 2026
    risk 0.32cvss 4.9epss 0.00

    FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

  • CVE-2023-6601MedJan 6, 2025
    risk 0.31cvss 4.7epss 0.00

    A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.

  • CVE-2026-90816MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be…

  • CVE-2026-18393MedAug 28, 2026
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service…

  • CVE-2025-69693MedMar 16, 2026
    risk 0.28cvss 5.4epss 0.00

    Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame…

  • CVE-2022-3965MedNov 13, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The…

  • CVE-2022-3964MedNov 13, 2022
    risk 0.28cvss 4.3epss 0.04

    A vulnerability classified as problematic has been found in ffmpeg. This affects an unknown part of the file libavcodec/rpzaenc.c of the component QuickTime RPZA Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. It is possible to initiate the…

  • CVE-2025-25473MedFeb 18, 2025
    risk 0.27cvss 5.3epss 0.00

    FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.

  • CVE-2025-22920MedFeb 18, 2025
    risk 0.27cvss 5.3epss 0.00

    A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).

  • CVE-2023-51796LowApr 19, 2024
    risk 0.23cvss 3.6epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame.

  • CVE-2025-12343LowFeb 18, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can…

  • CVE-2025-1816MedMar 2, 2025
    risk 0.21cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This affects the function audio_element_obu of the file libavformat/iamf_parse.c of the component IAMF File Handler. The manipulation of the argument num_parameters…

Page 15 of 28