Ffmpeg

Ffmpeg

548 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 19.08.2026 16:24:57
  • Zuletzt bearbeitet 09.09.2026 20:36:38

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an e...

  • EPSS 0.14%
  • Veröffentlicht 19.08.2026 16:24:01
  • Zuletzt bearbeitet 31.08.2026 20:37:35

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffe...

  • EPSS 0.13%
  • Veröffentlicht 06.08.2026 22:18:27
  • Zuletzt bearbeitet 01.09.2026 15:36:14

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file wit...

  • EPSS 0.13%
  • Veröffentlicht 06.08.2026 22:18:27
  • Zuletzt bearbeitet 01.09.2026 15:35:24

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a cr...

  • EPSS 0.14%
  • Veröffentlicht 06.08.2026 22:18:27
  • Zuletzt bearbeitet 01.09.2026 15:33:18

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid De...

  • EPSS 0.21%
  • Veröffentlicht 06.08.2026 22:18:27
  • Zuletzt bearbeitet 01.09.2026 15:32:31

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream ...

  • EPSS 0.15%
  • Veröffentlicht 06.08.2026 22:18:26
  • Zuletzt bearbeitet 01.09.2026 15:36:28

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. T...

Medienbericht Exploit
  • EPSS 0.35%
  • Veröffentlicht 24.07.2026 19:54:11
  • Zuletzt bearbeitet 07.08.2026 00:32:23

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. ...

  • EPSS 0.52%
  • Veröffentlicht 24.07.2026 19:46:25
  • Zuletzt bearbeitet 07.08.2026 00:35:29

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Att...

  • EPSS 0.31%
  • Veröffentlicht 24.07.2026 19:42:42
  • Zuletzt bearbeitet 07.08.2026 00:46:17

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers...