← Back

Ffmpeg

ffmpeg

Vendor: Ffmpeg • 480 CVEs

CVEs (480)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ffmpeg
1Ffmpeg
May 13, 2026
Apr 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c.
1Ffmpeg
1Ffmpeg
May 13, 2026
Apr 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.
1Ffmpeg
1Ffmpeg
May 13, 2026
Mar 20, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file.
1Ffmpeg
1Ffmpeg
May 13, 2026
Feb 9, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size...Show more
Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.Show less
1Ffmpeg
1Ffmpeg
May 13, 2026
Feb 9, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check...Show more
Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.Show less
1Ffmpeg
1Ffmpeg
May 13, 2026
Feb 9, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an...Show more
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.Show less
1Ffmpeg
1Ffmpeg
May 13, 2026
Jan 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of service (application crash) via vectors involving tile positions.
1Ffmpeg
1Ffmpeg
May 13, 2026
Jan 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving sample size...Show more
Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving sample size.Show less
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file.
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode.
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed AIFF file.
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure.
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file.
1Ffmpeg
1Ffmpeg
May 6, 2026
Dec 23, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted SWF file.
4Debian
FfmpegLibav+1 more
4Debian Linux
FfmpegLeap+1 more
May 6, 2026
Jun 16, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dr...Show more
The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.Show less