Ffmpeg

Ffmpeg

523 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 19.08.2026 16:29:03
  • Zuletzt bearbeitet 25.08.2026 03:16:56

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded heade...

  • EPSS 0.26%
  • Veröffentlicht 19.08.2026 16:28:19
  • Zuletzt bearbeitet 20.08.2026 15:18:38

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. ...

  • EPSS 0.12%
  • Veröffentlicht 19.08.2026 16:27:33
  • Zuletzt bearbeitet 21.08.2026 20:16:42

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets where long is 32 bits, i...

  • EPSS 0.14%
  • Veröffentlicht 19.08.2026 16:26:53
  • Zuletzt bearbeitet 21.08.2026 04:18:19

FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies ...

  • EPSS 0.41%
  • Veröffentlicht 19.08.2026 16:26:12
  • Zuletzt bearbeitet 21.08.2026 04:18:19

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overfl...

  • EPSS 0.14%
  • Veröffentlicht 19.08.2026 16:24:57
  • Zuletzt bearbeitet 21.08.2026 04:18:19

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an e...

  • EPSS 0.14%
  • Veröffentlicht 19.08.2026 16:24:01
  • Zuletzt bearbeitet 21.08.2026 04:18:19

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffe...

  • EPSS 0.13%
  • Veröffentlicht 06.08.2026 22:18:27
  • Zuletzt bearbeitet 07.08.2026 18:17:21

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file wit...

  • EPSS 0.13%
  • Veröffentlicht 06.08.2026 22:18:27
  • Zuletzt bearbeitet 07.08.2026 18:17:22

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a cr...

  • EPSS 0.14%
  • Veröffentlicht 06.08.2026 22:18:27
  • Zuletzt bearbeitet 08.08.2026 03:16:47

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid De...