CVE-2026-96611
- EPSS 0.12%
- Veröffentlicht 23.09.2026 14:18:54
- Zuletzt bearbeitet 26.09.2026 23:16:42
FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds checking, allowing values exceeding INT_MAX to become...
CVE-2026-90816
- EPSS 0.35%
- Veröffentlicht 14.09.2026 20:00:05
- Zuletzt bearbeitet 15.09.2026 20:19:20
A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. ...
CVE-2026-90815
- EPSS 0.24%
- Veröffentlicht 14.09.2026 19:45:05
- Zuletzt bearbeitet 15.09.2026 15:17:29
A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-of-bounds read...
CVE-2026-52296
- EPSS 0.16%
- Veröffentlicht 13.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 19:56:19
FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.
CVE-2026-52297
- EPSS 0.12%
- Veröffentlicht 13.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 19:56:19
FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
CVE-2026-30754
- EPSS 0.35%
- Veröffentlicht 08.09.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:17:02
A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP ...
CVE-2026-52295
- EPSS 0.17%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 13.09.2026 22:16:59
FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.
CVE-2026-38343
- EPSS 0.15%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 15:53:46
An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
CVE-2026-38344
- EPSS 0.15%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 08.09.2026 19:42:20
A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
CVE-2026-38345
- EPSS 0.15%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 08.09.2026 19:42:20
A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input.