CVE-2026-65704
- EPSS 0.12%
- Veröffentlicht 23.07.2026 18:55:41
- Zuletzt bearbeitet 07.08.2026 00:16:40
FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size wit...
CVE-2026-65703
- EPSS 0.2%
- Veröffentlicht 23.07.2026 18:52:19
- Zuletzt bearbeitet 07.08.2026 00:19:03
FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_...
CVE-2026-64835
- EPSS 0.33%
- Veröffentlicht 22.07.2026 17:24:05
- Zuletzt bearbeitet 28.07.2026 17:02:06
FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio fi...
CVE-2026-64834
- EPSS 0.5%
- Veröffentlicht 22.07.2026 17:06:07
- Zuletzt bearbeitet 28.07.2026 17:01:56
FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header func...
CVE-2026-64833
- EPSS 0.21%
- Veröffentlicht 22.07.2026 17:03:20
- Zuletzt bearbeitet 12.08.2026 20:17:48
FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet...
CVE-2026-64832
- EPSS 0.34%
- Veröffentlicht 22.07.2026 17:01:16
- Zuletzt bearbeitet 28.07.2026 17:01:21
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain...
CVE-2026-64831
- EPSS 0.46%
- Veröffentlicht 22.07.2026 16:35:43
- Zuletzt bearbeitet 28.07.2026 17:00:51
FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Att...
CVE-2026-64830
- EPSS 0.34%
- Veröffentlicht 22.07.2026 16:33:05
- Zuletzt bearbeitet 28.07.2026 17:00:32
FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs t...
CVE-2026-58049
- EPSS 0.28%
- Veröffentlicht 28.06.2026 02:16:30
- Zuletzt bearbeitet 17.08.2026 12:18:55
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can...
CVE-2026-8461
- EPSS 1.57%
- Veröffentlicht 18.06.2026 11:29:00
- Zuletzt bearbeitet 23.07.2026 12:18:51
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libav...