VYPR

Ffmpeg

by FFmpeg

Source repositories

CVEs (525)

  • CVE-2017-9994HigJun 28, 2017
    risk 0.51cvss 7.8epss 0.02

    libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or…

  • CVE-2017-9991HigJun 28, 2017
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly…

  • CVE-2012-5361HigMar 20, 2017
    risk 0.51cvss 7.8epss 0.03

    Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file.

  • CVE-2016-7502HigDec 23, 2016
    risk 0.51cvss 7.8epss 0.01

    The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode.

  • CVE-2016-7450HigDec 23, 2016
    risk 0.51cvss 7.8epss 0.01

    The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed AIFF file.

  • CVE-2016-6671HigDec 23, 2016
    risk 0.51cvss 7.8epss 0.02

    The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted SWF file.

  • CVE-2023-49502HigApr 19, 2024
    risk 0.50cvss 8.8epss 0.02

    Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.

  • CVE-2017-9993HigJun 28, 2017
    risk 0.50cvss 7.5epss 0.16

    FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.

  • CVE-2026-64834HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.01

    FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a…

  • CVE-2025-63757HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.00

    Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

  • CVE-2025-57616HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleaved method allows an attacker to cause a denial of service or memory corruption. The method violates Rust's aliasing rules by modifying a data structure through…

  • CVE-2025-57614HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in the cached method allows an attacker to cause a denial of service or potentially execute arbitrary code. The vulnerability occurs when dimension parameters are…

  • CVE-2025-57613HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input() constructor function allows an attacker to cause a denial of service. The vulnerability is triggered when the avio_alloc_context() call fails and returns…

  • CVE-2025-57612HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name() method allows an attacker to cause a denial of service. The vulnerability exists because the method fails to check for a NULL return value from the…

  • CVE-2023-6603HigDec 31, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.

  • CVE-2021-38291HigAug 12, 2021
    risk 0.49cvss 7.5epss 0.03

    FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.

  • CVE-2020-20451HigMay 25, 2021
    risk 0.49cvss 7.5epss 0.01

    Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.

  • CVE-2020-20450HigMay 25, 2021
    risk 0.49cvss 7.5epss 0.01

    FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavformat/aviobuf.c, which could cause a Denial of Service.

  • CVE-2020-21041HigMay 24, 2021
    risk 0.49cvss 7.5epss 0.02

    Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service

  • CVE-2012-2805HigAug 28, 2017
    risk 0.49cvss 7.5epss 0.02

    Unspecified vulnerability in FFMPEG 0.10 allows remote attackers to cause a denial of service.

Page 6 of 27