CVE-2026-64832
- EPSS 0.34%
- Veröffentlicht 22.07.2026 17:01:16
- Zuletzt bearbeitet 28.07.2026 17:01:21
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain...
CVE-2026-64831
- EPSS 0.46%
- Veröffentlicht 22.07.2026 16:35:43
- Zuletzt bearbeitet 28.07.2026 17:00:51
FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Att...
CVE-2026-64830
- EPSS 0.34%
- Veröffentlicht 22.07.2026 16:33:05
- Zuletzt bearbeitet 28.07.2026 17:00:32
FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs t...
CVE-2026-58049
- EPSS 0.28%
- Veröffentlicht 28.06.2026 02:16:30
- Zuletzt bearbeitet 01.09.2026 13:19:51
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can...
CVE-2026-8461
- EPSS 1.57%
- Veröffentlicht 18.06.2026 11:29:00
- Zuletzt bearbeitet 23.07.2026 12:18:51
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libav...
CVE-2026-40962
- EPSS 0.13%
- Veröffentlicht 16.04.2026 01:33:37
- Zuletzt bearbeitet 20.04.2026 19:54:35
FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.
CVE-2026-30997
- EPSS 0.34%
- Veröffentlicht 13.04.2026 00:00:00
- Zuletzt bearbeitet 23.04.2026 20:12:35
An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2026-30998
- EPSS 0.4%
- Veröffentlicht 13.04.2026 00:00:00
- Zuletzt bearbeitet 23.04.2026 20:11:49
An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.
CVE-2026-30999
- EPSS 0.45%
- Veröffentlicht 13.04.2026 00:00:00
- Zuletzt bearbeitet 23.04.2026 20:10:36
A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-69693
- EPSS 0.27%
- Veröffentlicht 16.03.2026 00:00:00
- Zuletzt bearbeitet 19.03.2026 14:19:12
Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base ...