← Back

Ffmpeg

ffmpeg

Vendor: Ffmpeg • 480 CVEs

CVEs (480)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Dec 7, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
libavcodec/alsdec.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via a crafted block length, which triggers an out-of-bounds write.
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Dec 7, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Off-by-one error in the adpcm_decode_frame function in libavcodec/adpcm.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via crafted DK4 data, which triggers an out-of-bounds array access.
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The field_end function in libavcodec/h264.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted H.264 data, related to an SPS and slice mismatch and an out-of-bounds array access.
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted Huffyuv data, related to an out-of-bounds write and (1) unchecked return codes from the init_vlc function a...Show more
libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted Huffyuv data, related to an out-of-bounds write and (1) unchecked return codes from the init_vlc function and (2) "len==0 cases."Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remote attackers to have unspecified impact via crafted H.264 video data, r...Show more
The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remote attackers to have unspecified impact via crafted H.264 video data, related to an out-of-bounds array access.Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The aac_decode_init function in libavcodec/aacdec.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large number of channels in an AAC file, which triggers an out...Show more
The aac_decode_init function in libavcodec/aacdec.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large number of channels in an AAC file, which triggers an out-of-bounds array access.Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The vqa_decode_chunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large (1) cbp0 or (2) cbpz chunk in Westwood Studios VQA Vi...Show more
The vqa_decode_chunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large (1) cbp0 or (2) cbpz chunk in Westwood Studios VQA Video file, which triggers an out-of-bounds write.Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before 1.1.2 performs an incorrect calculation for an "end pointer," which allows remote attackers to have an unspecified impact via crafted GIF data that t...Show more
The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before 1.1.2 performs an incorrect calculation for an "end pointer," which allows remote attackers to have an unspecified impact via crafted GIF data that triggers an out-of-bounds array access.Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in the rle_decode function in libavcodec/sanm.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via crafted LucasArts Smush video data.
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple integer overflows in the process_frame_obj function in libavcodec/sanm.c in FFmpeg before 1.1.2 allow remote attackers to have an unspecified impact via crafted image dimensions in LucasArts Smush video data, wh...Show more
Multiple integer overflows in the process_frame_obj function in libavcodec/sanm.c in FFmpeg before 1.1.2 allow remote attackers to have an unspecified impact via crafted image dimensions in LucasArts Smush video data, which triggers an out-of-bounds array access.Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The avcodec_decode_audio4 function in libavcodec/utils.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 allows remote attackers to trigger memory corruption via vectors related to the channel layout.
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL poin...Show more
The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL pointer dereference via crafted picture data.Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The av_reallocp_array function in libavutil/mem.c in FFmpeg before 2.0.1 has an unspecified impact and remote vectors related to a "wrong return code" and a resultant NULL pointer dereference.
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The kempf_decode_tile function in libavcodec/g2meet.c in FFmpeg before 2.0.1 allows remote attackers to cause a denial of service (out-of-bounds heap write) via a G2M4 encoded file.
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
libavfilter in FFmpeg before 2.0.1 has unspecified impact and remote vectors related to a crafted "plane," which triggers an out-of-bounds heap write.
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The advance_line function in libavcodec/targa.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted Targa image data, related to an out-of-bounds array access.
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The old_codec37 function in libavcodec/sanm.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted LucasArts Smush data that has a large size when decoded, related to an out-of-bounds...Show more
The old_codec37 function in libavcodec/sanm.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted LucasArts Smush data that has a large size when decoded, related to an out-of-bounds array access.Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple integer overflows in the (1) old_codec37 and (2) old_codec47 functions in libavcodec/sanm.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via crafted LucasArts Smush data, which tri...Show more
Multiple integer overflows in the (1) old_codec37 and (2) old_codec47 functions in libavcodec/sanm.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via crafted LucasArts Smush data, which triggers an out-of-bounds array access.Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The ff_add_png_paeth_prediction function in libavcodec/pngdec.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via a crafted PNG image, related to an out-of-bounds array access.
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The (1) doubles2str and (2) shorts2str functions in libavcodec/tiff.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via a crafted TIFF image, related to an out-of-bounds array access.