Ffmpeg

Ffmpeg

548 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 22.07.2026 17:01:16
  • Zuletzt bearbeitet 28.07.2026 17:01:21

FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain...

  • EPSS 0.46%
  • Veröffentlicht 22.07.2026 16:35:43
  • Zuletzt bearbeitet 28.07.2026 17:00:51

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Att...

  • EPSS 0.34%
  • Veröffentlicht 22.07.2026 16:33:05
  • Zuletzt bearbeitet 28.07.2026 17:00:32

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs t...

  • EPSS 0.28%
  • Veröffentlicht 28.06.2026 02:16:30
  • Zuletzt bearbeitet 01.09.2026 13:19:51

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can...

Medienbericht
  • EPSS 1.57%
  • Veröffentlicht 18.06.2026 11:29:00
  • Zuletzt bearbeitet 23.07.2026 12:18:51

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libav...

  • EPSS 0.13%
  • Veröffentlicht 16.04.2026 01:33:37
  • Zuletzt bearbeitet 20.04.2026 19:54:35

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 13.04.2026 00:00:00
  • Zuletzt bearbeitet 23.04.2026 20:12:35

An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 13.04.2026 00:00:00
  • Zuletzt bearbeitet 23.04.2026 20:11:49

An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 13.04.2026 00:00:00
  • Zuletzt bearbeitet 23.04.2026 20:10:36

A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • EPSS 0.27%
  • Veröffentlicht 16.03.2026 00:00:00
  • Zuletzt bearbeitet 19.03.2026 14:19:12

Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base ...