Ffmpeg

Ffmpeg

548 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 27.08.2026 00:00:00
  • Zuletzt bearbeitet 09.09.2026 15:53:46

An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

  • EPSS 0.15%
  • Veröffentlicht 27.08.2026 00:00:00
  • Zuletzt bearbeitet 08.09.2026 19:42:20

A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • EPSS 0.32%
  • Veröffentlicht 27.08.2026 00:00:00
  • Zuletzt bearbeitet 09.09.2026 15:53:46

An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.

  • EPSS 0.32%
  • Veröffentlicht 27.08.2026 00:00:00
  • Zuletzt bearbeitet 09.09.2026 15:53:46

An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.

  • EPSS 0.32%
  • Veröffentlicht 27.08.2026 00:00:00
  • Zuletzt bearbeitet 09.09.2026 15:53:46

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

  • EPSS 0.12%
  • Veröffentlicht 19.08.2026 16:29:03
  • Zuletzt bearbeitet 31.08.2026 20:37:35

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded heade...

  • EPSS 0.26%
  • Veröffentlicht 19.08.2026 16:28:19
  • Zuletzt bearbeitet 31.08.2026 20:37:35

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. ...

  • EPSS 0.12%
  • Veröffentlicht 19.08.2026 16:27:33
  • Zuletzt bearbeitet 31.08.2026 20:37:35

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets where long is 32 bits, i...

  • EPSS 0.14%
  • Veröffentlicht 19.08.2026 16:26:53
  • Zuletzt bearbeitet 31.08.2026 20:37:35

FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies ...

  • EPSS 0.41%
  • Veröffentlicht 19.08.2026 16:26:12
  • Zuletzt bearbeitet 31.08.2026 20:37:35

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overfl...