VYPR

Ffmpeg

by FFmpeg

Source repositories

CVEs (548)

  • CVE-2014-125015HigJun 18, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in FFmpeg 2.0. Affected is the function read_var_block_data. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.

  • CVE-2026-75147HigAug 19, 2026
    risk 0.46cvss 7.1epss 0.00

    FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload…

  • CVE-2026-64833HigJul 22, 2026
    risk 0.46cvss 7.1epss 0.00

    FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can…

  • CVE-2023-51797MedApr 19, 2024
    risk 0.44cvss 6.7epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame

  • CVE-2024-32228MedJul 1, 2024
    risk 0.43cvss 6.6epss 0.00

    FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

  • CVE-2017-9608MedDec 27, 2017
    risk 0.43cvss 6.5epss 0.05

    The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.

  • CVE-2026-38345MedAug 28, 2026
    risk 0.42cvss 6.5epss 0.00

    A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-38343MedAug 28, 2026
    risk 0.42cvss 6.5epss 0.00

    An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

  • CVE-2026-66038MedJul 24, 2026
    risk 0.42cvss 6.5epss 0.00

    FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The…

  • CVE-2026-66037MedJul 24, 2026
    risk 0.42cvss 6.5epss 0.00

    FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field.…

  • CVE-2026-12706MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed buffer, but a subsequent reallocation of that same buffer during move-table processing leaves the pointer dangling. An attacker…

  • CVE-2026-6385MedApr 15, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment…

  • CVE-2026-30999HigApr 13, 2026
    risk 0.42cvss 7.5epss 0.00

    A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-30998HigApr 13, 2026
    risk 0.42cvss 7.5epss 0.00

    An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.

  • CVE-2026-30997HigApr 13, 2026
    risk 0.42cvss 7.5epss 0.00

    An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-22919MedFeb 18, 2025
    risk 0.42cvss 6.5epss 0.00

    A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.

  • CVE-2025-25469MedFeb 18, 2025
    risk 0.42cvss 6.5epss 0.00

    FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.

  • CVE-2025-25468MedFeb 18, 2025
    risk 0.42cvss 6.5epss 0.00

    FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.

  • CVE-2025-22921MedFeb 18, 2025
    risk 0.42cvss 6.5epss 0.00

    FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.

  • CVE-2020-36138HigAug 11, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).

Page 8 of 28