CVE-2025-59729
- EPSS 0.02%
- Veröffentlicht 06.10.2025 08:08:46
- Zuletzt bearbeitet 06.10.2025 14:56:21
When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the duration from before the start of the allocated buffer. If we load a DHAV file that is larger than MAX_DURATION_BUFFER_SIZE bytes (...
CVE-2025-9951
- EPSS 0.34%
- Veröffentlicht 09.09.2025 13:54:08
- Zuletzt bearbeitet 09.09.2025 16:28:43
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
CVE-2024-55069
- EPSS 0.3%
- Veröffentlicht 02.05.2025 00:00:00
- Zuletzt bearbeitet 03.06.2025 18:13:05
ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.
CVE-2025-1816
- EPSS 0.25%
- Veröffentlicht 02.03.2025 14:15:34
- Zuletzt bearbeitet 03.03.2025 20:15:44
A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This affects the function audio_element_obu of the file libavformat/iamf_parse.c of the component IAMF File Handler. The manipulation o...
CVE-2025-1594
- EPSS 0.35%
- Veröffentlicht 23.02.2025 21:15:09
- Zuletzt bearbeitet 03.06.2025 18:04:04
A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow....
CVE-2025-22919
- EPSS 0.08%
- Veröffentlicht 18.02.2025 23:15:10
- Zuletzt bearbeitet 03.11.2025 21:19:13
A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.
CVE-2025-22920
- EPSS 0.14%
- Veröffentlicht 18.02.2025 23:15:10
- Zuletzt bearbeitet 19.02.2025 22:15:23
A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).
CVE-2025-25471
- EPSS 0.05%
- Veröffentlicht 18.02.2025 23:15:10
- Zuletzt bearbeitet 20.02.2025 21:15:25
FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.
CVE-2025-25473
- EPSS 0.14%
- Veröffentlicht 18.02.2025 23:15:10
- Zuletzt bearbeitet 16.12.2025 19:15:57
FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.
CVE-2025-22921
- EPSS 0.17%
- Veröffentlicht 18.02.2025 22:15:18
- Zuletzt bearbeitet 12.01.2026 13:08:11
FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.