VYPR

Vendor CVEs

FFmpeg

All CVEs

549 total · sorted by risk
  • CVE-2026-66038MedJul 24, 2026
    risk 0.42cvss 6.5epss 0.00

    FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The…

  • CVE-2026-66037MedJul 24, 2026
    risk 0.42cvss 6.5epss 0.00

    FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field.…

  • CVE-2026-12706MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed buffer, but a subsequent reallocation of that same buffer during move-table processing leaves the pointer dangling. An attacker…

  • CVE-2026-6385MedApr 15, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment…

  • CVE-2026-30999HigApr 13, 2026
    risk 0.42cvss 7.5epss 0.00

    A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-30998HigApr 13, 2026
    risk 0.42cvss 7.5epss 0.00

    An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.

  • CVE-2026-30997HigApr 13, 2026
    risk 0.42cvss 7.5epss 0.00

    An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-22919MedFeb 18, 2025
    risk 0.42cvss 6.5epss 0.00

    A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.

  • CVE-2025-25469MedFeb 18, 2025
    risk 0.42cvss 6.5epss 0.00

    FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.

  • CVE-2025-25468MedFeb 18, 2025
    risk 0.42cvss 6.5epss 0.00

    FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.

  • CVE-2025-22921MedFeb 18, 2025
    risk 0.42cvss 6.5epss 0.00

    FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.

  • CVE-2020-36138HigAug 11, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).

  • CVE-2020-20902MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    A CWE-125: Out-of-bounds read vulnerability exists in long_term_filter function in g729postfilter.c in FFmpeg 4.2.1 during computation of the denominator of pseudo-normalized correlation R'(0), that could result in disclosure of information.

  • CVE-2020-21697MedAug 10, 2021
    risk 0.42cvss 6.5epss 0.01

    A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a denial of service (DOS) via a crafted avi file.

  • CVE-2020-22056MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossover.c.

  • CVE-2020-22054MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.

  • CVE-2020-22051MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c.

  • CVE-2020-22049MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.

  • CVE-2020-22048MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.

  • CVE-2020-22046MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.

  • CVE-2020-22044MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c.

  • CVE-2020-22043MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c.

  • CVE-2020-22042MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory leak in the link_filter_inouts function in libavfilter/graphparser.c.

  • CVE-2020-22041MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc.

  • CVE-2020-22040MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.

  • CVE-2020-22039MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the inavi_add_ientry function.

  • CVE-2020-22038MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c.

  • CVE-2020-22037MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.02

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.

  • CVE-2020-22033MedMay 27, 2021
    risk 0.42cvss 6.5epss 0.01

    A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a remote malicious user cause a Denial of Service.

  • CVE-2020-22028MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_vertically_8 at libavfilter/vf_avgblur.c, which could cause a remote Denial of Service.

  • CVE-2020-22026MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function at libavfilter/af_tremolo.c, which could let a remote malicious user cause a Denial of Service.

  • CVE-2020-22024MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in libavfilter/vf_lagfun.c, which could let a remote malicious user cause Denial of Service.

  • CVE-2020-22021MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service.

  • CVE-2020-22020MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause a Denial of Service.

  • CVE-2020-22019MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service.

  • CVE-2020-20453MedMay 25, 2021
    risk 0.42cvss 6.5epss 0.02

    FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aaccoder, which allows a remote malicious user to cause a Denial of Service

  • CVE-2020-20448MedMay 25, 2021
    risk 0.42cvss 6.5epss 0.01

    FFmpeg 4.1.3 is affected by a Divide By Zero issue via libavcodec/ratecontrol.c, which allows a remote malicious user to cause a Denial of Service.

  • CVE-2020-20446MedMay 25, 2021
    risk 0.42cvss 6.5epss 0.02

    FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aacpsy.c, which allows a remote malicious user to cause a Denial of Service.

  • CVE-2020-20445MedMay 25, 2021
    risk 0.42cvss 6.5epss 0.02

    FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/lpc.h, which allows a remote malicious user to cause a Denial of Service.

  • CVE-2020-35965HigJan 4, 2021
    risk 0.42cvss 7.5epss 0.02

    decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.

  • CVE-2019-13390MedJul 7, 2019
    risk 0.42cvss 6.5epss 0.02

    In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat/rawenc.c.

  • CVE-2018-15822HigAug 23, 2018
    risk 0.42cvss 7.5epss 0.03

    The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.

  • CVE-2018-7751MedApr 24, 2018
    risk 0.42cvss 6.5epss 0.02

    The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file.

  • CVE-2018-10001MedApr 11, 2018
    risk 0.42cvss 6.5epss 0.02

    The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file.

  • CVE-2018-6912MedFeb 12, 2018
    risk 0.42cvss 6.5epss 0.02

    The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.

  • CVE-2018-6392MedJan 29, 2018
    risk 0.42cvss 6.5epss 0.02

    The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows remote attackers to cause a denial of service (out-of-array access) via a crafted MP4 file.

  • CVE-2017-1000460MedJan 3, 2018
    risk 0.42cvss 6.5epss 0.01

    In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.

  • CVE-2017-17555MedDec 12, 2017
    risk 0.42cvss 6.5epss 0.01

    The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.

  • CVE-2017-17081MedNov 30, 2017
    risk 0.42cvss 6.5epss 0.02

    The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does not properly validate widths and heights, which allows remote attackers to cause a denial of service (integer signedness error and out-of-array read) via a crafted MPEG file.

  • CVE-2017-15186MedOct 24, 2017
    risk 0.42cvss 6.5epss 0.02

    Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.

Page 4 of 11