VYPR

Ffmpeg

by FFmpeg

Source repositories

CVEs (548)

  • CVE-2025-25471MedFeb 18, 2025
    risk 0.21cvss 4.3epss 0.00

    FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.

  • CVE-2025-1373LowFeb 17, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function mov_read_trak of the file libavformat/mov.c of the component MOV Parser. The manipulation leads to null pointer dereference. Local access is required to…

  • CVE-2026-52297LowSep 13, 2026
    risk 0.12cvss 2.9epss 0.00

    FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

  • CVE-2026-52296LowSep 13, 2026
    risk 0.12cvss 2.9epss 0.00

    FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

  • CVE-2026-52295LowSep 1, 2026
    risk 0.12cvss 2.9epss 0.00

    FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.

  • CVE-2009-4637Feb 10, 2010
    risk 0.04cvss —epss 0.17

    FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow.

  • CVE-2008-3162Jul 14, 2008
    risk 0.04cvss —epss 0.09

    Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted STR file that interleaves audio and video sectors.

  • CVE-2009-4635Feb 10, 2010
    risk 0.01cvss —epss 0.08

    FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted MOV container with improperly ordered tags that cause (1) mov.c and (2) utils.c to use inconsistent codec types and identifiers, leading to processing of a…

  • CVE-2009-4634Feb 10, 2010
    risk 0.01cvss —epss 0.07

    Multiple integer underflows in FFmpeg 0.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted file that (1) bypasses a validation check in vorbis_dec.c and triggers a wraparound of the stack pointer, or (2) access a pointer from…

  • CVE-2009-4633Feb 10, 2010
    risk 0.01cvss —epss 0.08

    vorbis_dec.c in FFmpeg 0.5 uses an assignment operator when a comparison operator was intended, which might allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted file that modifies a loop counter and triggers a heap-based buffer…

  • CVE-2009-0385Feb 2, 2009
    risk 0.01cvss —epss 0.07

    Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.

  • CVE-2025-10256MedFeb 18, 2026
    risk 0.00cvss 5.3epss 0.00

    A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a…

  • CVE-2025-0518MedJan 16, 2025
    risk 0.00cvss 5.3epss 0.00

    Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C . This issue affects FFmpeg: 7.1. …

  • CVE-2024-36613MedJan 3, 2025
    risk 0.00cvss 6.2epss 0.00

    FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.

  • CVE-2024-35365HigJan 3, 2025
    risk 0.00cvss 8.8epss 0.01

    FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.

  • CVE-2024-35368CriNov 29, 2024
    risk 0.00cvss 9.8epss 0.01

    FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.

  • CVE-2024-35367CriNov 29, 2024
    risk 0.00cvss 9.1epss 0.01

    FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer

  • CVE-2024-35366CriNov 29, 2024
    risk 0.00cvss 9.1epss 0.01

    FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without…

  • CVE-2024-36616MedNov 29, 2024
    risk 0.00cvss 6.5epss 0.01

    An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.

  • CVE-2024-36615MedNov 29, 2024
    risk 0.00cvss 5.9epss 0.00

    FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.

Page 16 of 28