Ffmpeg

Ffmpeg

548 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 08.10.2026 17:30:28
  • Zuletzt bearbeitet 08.10.2026 21:04:38

FFmpeg before 8.1.3 contains a protection mechanism failure in the HLS demuxer that allows attackers to bypass protocol and allowed_extensions restrictions when opening child playlists. Attackers can supply a crafted master playlist whose child playl...

  • EPSS 0.27%
  • Veröffentlicht 08.10.2026 17:30:28
  • Zuletzt bearbeitet 08.10.2026 21:04:38

FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without validating the Location URL. Malicious RTSP servers can redirect FFmpeg...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 08.10.2026 17:30:27
  • Zuletzt bearbeitet 09.10.2026 12:17:09

FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any redirect limit. Attackers controlling an RTSP server can answer every request with a 302 redirect to i...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 08.10.2026 17:30:26
  • Zuletzt bearbeitet 08.10.2026 21:04:38

FFmpeg before 8.1.3 contains an infinite loop vulnerability in the HLS demuxer that allows remote attackers to cause denial of service because parse_playlist() accepts Master Playlist tags inside Media Playlists. Attackers can trick victims into open...

  • EPSS 0.08%
  • Veröffentlicht 08.10.2026 15:28:43
  • Zuletzt bearbeitet 08.10.2026 21:04:38

FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively frees AVEncryptionInitInfo linked lists built by the MOV demuxer's mov_read_pssh(). Attackers can suppl...

  • EPSS 0.11%
  • Veröffentlicht 08.10.2026 15:28:42
  • Zuletzt bearbeitet 08.10.2026 21:04:38

FFmpeg through 9.0.2 contains a denial of service vulnerability in the DASH demuxer that allows attackers to trigger an infinite loop by supplying an empty SegmentTemplate media URL. Attackers can craft an .mpd manifest declaring SegmentTemplate medi...

  • EPSS 0.19%
  • Veröffentlicht 08.10.2026 15:28:41
  • Zuletzt bearbeitet 08.10.2026 21:04:38

FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture ...

  • EPSS 0.12%
  • Veröffentlicht 08.10.2026 15:28:41
  • Zuletzt bearbeitet 08.10.2026 21:04:38

FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0. Attackers can supply crafted Matroska T.35 BlockAdditional...

  • EPSS 0.14%
  • Veröffentlicht 08.10.2026 15:28:40
  • Zuletzt bearbeitet 08.10.2026 21:04:38

FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Network attackers can intercept https, rtmps, or tls conn...

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 27.09.2026 09:07:35
  • Zuletzt bearbeitet 02.10.2026 18:57:08

MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_ce...