CVE-2026-66038
- EPSS 0.25%
- Veröffentlicht 24.07.2026 19:39:27
- Zuletzt bearbeitet 07.08.2026 00:54:32
FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than...
CVE-2026-66037
- EPSS 0.21%
- Veröffentlicht 24.07.2026 19:36:53
- Zuletzt bearbeitet 07.08.2026 00:58:46
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a ...
CVE-2026-66036
- EPSS 0.28%
- Veröffentlicht 24.07.2026 19:34:16
- Zuletzt bearbeitet 07.08.2026 01:05:17
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when fi...
CVE-2026-65706
- EPSS 0.13%
- Veröffentlicht 23.07.2026 19:05:11
- Zuletzt bearbeitet 07.08.2026 00:21:44
FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function...
CVE-2026-65705
- EPSS 0.13%
- Veröffentlicht 23.07.2026 19:00:36
- Zuletzt bearbeitet 07.08.2026 00:20:32
FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via ...
CVE-2026-65704
- EPSS 0.12%
- Veröffentlicht 23.07.2026 18:55:41
- Zuletzt bearbeitet 07.08.2026 00:16:40
FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size wit...
CVE-2026-65703
- EPSS 0.2%
- Veröffentlicht 23.07.2026 18:52:19
- Zuletzt bearbeitet 07.08.2026 00:19:03
FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_...
CVE-2026-64835
- EPSS 0.33%
- Veröffentlicht 22.07.2026 17:24:05
- Zuletzt bearbeitet 28.07.2026 17:02:06
FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio fi...
CVE-2026-64834
- EPSS 0.5%
- Veröffentlicht 22.07.2026 17:06:07
- Zuletzt bearbeitet 28.07.2026 17:01:56
FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header func...
CVE-2026-64833
- EPSS 0.21%
- Veröffentlicht 22.07.2026 17:03:20
- Zuletzt bearbeitet 12.08.2026 20:17:48
FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet...