Ffmpeg

Ffmpeg

523 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 06.08.2026 22:18:27
  • Zuletzt bearbeitet 07.08.2026 18:17:22

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream ...

  • EPSS 0.15%
  • Veröffentlicht 06.08.2026 22:18:26
  • Zuletzt bearbeitet 07.08.2026 18:17:21

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. T...

Medienbericht Exploit
  • EPSS 0.35%
  • Veröffentlicht 24.07.2026 19:54:11
  • Zuletzt bearbeitet 07.08.2026 00:32:23

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. ...

  • EPSS 0.52%
  • Veröffentlicht 24.07.2026 19:46:25
  • Zuletzt bearbeitet 07.08.2026 00:35:29

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Att...

  • EPSS 0.31%
  • Veröffentlicht 24.07.2026 19:42:42
  • Zuletzt bearbeitet 07.08.2026 00:46:17

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers...

  • EPSS 0.25%
  • Veröffentlicht 24.07.2026 19:39:27
  • Zuletzt bearbeitet 07.08.2026 00:54:32

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than...

  • EPSS 0.21%
  • Veröffentlicht 24.07.2026 19:36:53
  • Zuletzt bearbeitet 07.08.2026 00:58:46

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a ...

Medienbericht
  • EPSS 0.28%
  • Veröffentlicht 24.07.2026 19:34:16
  • Zuletzt bearbeitet 07.08.2026 01:05:17

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when fi...

  • EPSS 0.13%
  • Veröffentlicht 23.07.2026 19:05:11
  • Zuletzt bearbeitet 07.08.2026 00:21:44

FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function...

  • EPSS 0.13%
  • Veröffentlicht 23.07.2026 19:00:36
  • Zuletzt bearbeitet 07.08.2026 00:20:32

FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via ...