CVE-2025-59734
- EPSS 0.02%
- Veröffentlicht 06.10.2025 08:09:44
- Zuletzt bearbeitet 06.10.2025 14:56:21
It is possible to cause an use-after-free write in SANM decoding with a carefully crafted animation using subversion <2. When a STOR chunk is present, a subsequent FOBJ chunk will be saved in ctx->stored_frame. Stored frames can later be referenced ...
CVE-2025-59733
- EPSS 0.02%
- Veröffentlicht 06.10.2025 08:09:37
- Zuletzt bearbeitet 06.10.2025 14:56:21
When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that all image channels have the same pixel type (and size), and that if there are four channels, the first four are "B", "G", "R" and "A". The channel p...
CVE-2025-59732
- EPSS 0.02%
- Veröffentlicht 06.10.2025 08:09:31
- Zuletzt bearbeitet 06.10.2025 14:56:21
When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that the height and width are divisible by 8. If the height or width of the image is not divisible by 8, the copy loops at [0] and [1] will continue to ...
CVE-2025-59731
- EPSS 0.02%
- Veröffentlicht 06.10.2025 08:09:23
- Zuletzt bearbeitet 06.10.2025 14:56:21
When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to calculate the output data. We read rle_raw_size from the input file at [0], we decompress and decod...
CVE-2025-59730
- EPSS 0.02%
- Veröffentlicht 06.10.2025 08:09:11
- Zuletzt bearbeitet 06.10.2025 14:56:21
When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it. Frames encoded with codec 48 can specify their resolution (width x height). A buffer of appropriate size is allocated depending...
CVE-2025-59729
- EPSS 0.03%
- Veröffentlicht 06.10.2025 08:08:46
- Zuletzt bearbeitet 06.10.2025 14:56:21
When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the duration from before the start of the allocated buffer. If we load a DHAV file that is larger than MAX_DURATION_BUFFER_SIZE bytes (...
CVE-2025-9951
- EPSS 0.3%
- Veröffentlicht 09.09.2025 13:54:08
- Zuletzt bearbeitet 09.09.2025 16:28:43
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
CVE-2024-55069
- EPSS 0.05%
- Veröffentlicht 02.05.2025 00:00:00
- Zuletzt bearbeitet 03.06.2025 18:13:05
ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.
CVE-2025-1816
- EPSS 0.14%
- Veröffentlicht 02.03.2025 14:15:34
- Zuletzt bearbeitet 03.03.2025 20:15:44
A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This affects the function audio_element_obu of the file libavformat/iamf_parse.c of the component IAMF File Handler. The manipulation o...
CVE-2025-1594
- EPSS 0.16%
- Veröffentlicht 23.02.2025 21:15:09
- Zuletzt bearbeitet 03.06.2025 18:04:04
A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow....