VYPR

Ffmpeg

by FFmpeg

Source repositories

CVEs (525)

  • CVE-2022-48434HigMar 29, 2023
    risk 0.53cvss 8.1epss 0.02

    libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a…

  • CVE-2023-51795HigApr 19, 2024
    risk 0.52cvss 8.0epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame

  • CVE-2023-49501HigApr 19, 2024
    risk 0.52cvss 8.0epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.

  • CVE-2023-49528HigApr 12, 2024
    risk 0.52cvss 8.0epss 0.00

    Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.

  • CVE-2026-70632HigAug 6, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode()…

  • CVE-2026-70628HigAug 6, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the…

  • CVE-2026-65706HigJul 23, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row…

  • CVE-2026-65705HigJul 23, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When…

  • CVE-2026-65704HigJul 23, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking,…

  • CVE-2026-65703HigJul 23, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails…

  • CVE-2024-32230HigJul 1, 2024
    risk 0.51cvss 7.8epss 0.00

    FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0

  • CVE-2023-51794HigApr 26, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.

  • CVE-2023-51798HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.

  • CVE-2023-51793HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane.

  • CVE-2023-51791HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.

  • CVE-2020-24995HigMar 30, 2021
    risk 0.51cvss 7.8epss 0.01

    Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to execute arbitrary code (local).

  • CVE-2017-11719HigJul 28, 2017
    risk 0.51cvss 7.8epss 0.02

    The dnxhd_decode_header function in libavcodec/dnxhddec.c in FFmpeg 3.0 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a crafted DNxHD file.

  • CVE-2017-11399HigJul 17, 2017
    risk 0.51cvss 7.8epss 0.02

    Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg 2.4 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access and application crash) or possibly have unspecified other impact via a crafted APE file.

  • CVE-2017-9996HigJun 28, 2017
    risk 0.51cvss 7.8epss 0.02

    The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial of service (heap-based buffer…

  • CVE-2017-9995HigJun 28, 2017
    risk 0.51cvss 7.8epss 0.02

    libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

Page 5 of 27