📦 Ffmpeg

by Ffmpeg

🔍 What is Ffmpeg?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-35368

CRITICAL CVSS 9.8 Nov 29, 2024

CVE-2024-35368 is a double-free vulnerability in FFmpeg's rkmppdec.c component that allows memory corruption when processing certain media files. Attackers can exploit this to potentially execute arbi...

CVE-2024-35366

CRITICAL CVSS 9.1 Nov 29, 2024

This CVE-2024-35366 is an integer overflow vulnerability in FFmpeg's libavformat module that allows attackers to cause denial of service or potentially execute arbitrary code by providing malicious in...

CVE-2024-31581

CRITICAL CVSS 9.8 Apr 17, 2024

CVE-2024-31581 is an improper array index validation vulnerability in FFmpeg's H.266 video codec parser that allows attackers to trigger undefined behavior, potentially leading to crashes or arbitrary...

CVE-2024-22860

CRITICAL CVSS 9.8 Jan 27, 2024

This integer overflow vulnerability in FFmpeg's JPEG XL Animation decoder allows remote attackers to execute arbitrary code by sending specially crafted files. It affects all systems running FFmpeg ve...

CVE-2025-63757

HIGH CVSS 7.5 Dec 18, 2025

An integer overflow vulnerability in FFmpeg's libswscale component allows attackers to cause heap corruption when processing specially crafted YUV video files. This affects any application using FFmpe...

CVE-2023-6605

HIGH CVSS 7.2 Jan 6, 2025

This vulnerability in FFmpeg's DASH playlist support allows attackers to make arbitrary HTTP GET requests from the system running FFmpeg by providing a maliciously crafted DASH playlist. This affects ...

CVE-2024-35365

HIGH CVSS 8.8 Jan 3, 2025

CVE-2024-35365 is a double-free vulnerability in FFmpeg's audio stream initialization function that could allow attackers to execute arbitrary code or cause denial of service. This affects systems usi...

CVE-2023-6603

HIGH CVSS 7.5 Dec 31, 2024

This vulnerability in FFmpeg's HLS playlist parsing allows attackers to cause denial of service by triggering a null pointer dereference during initialization with a maliciously crafted HLS playlist. ...

CVE-2023-51794

HIGH CVSS 7.8 Apr 26, 2024

A buffer overflow vulnerability in FFmpeg's stereowiden audio filter allows local attackers to execute arbitrary code by providing specially crafted audio input. This affects systems running vulnerabl...

CVE-2023-50008

HIGH CVSS 7.8 Apr 19, 2024

CVE-2023-50008 is a buffer overflow vulnerability in FFmpeg's colorcorrect filter that allows attackers to cause memory corruption through improper memory allocation. This affects systems using FFmpeg...

CVE-2023-50010

HIGH CVSS 7.8 Apr 19, 2024

This CVE describes a buffer over-read vulnerability in FFmpeg's gradfun filter SSE2 optimization. Attackers can exploit this to read memory beyond allocated buffers, potentially leaking sensitive info...

CVE-2023-51793

HIGH CVSS 7.8 Apr 19, 2024

A buffer overflow vulnerability in FFmpeg's image_copy_plane function allows local attackers to execute arbitrary code. This affects systems running vulnerable FFmpeg versions where an attacker has lo...

CVE-2023-51798

HIGH CVSS 7.8 Apr 19, 2024

This CVE describes a buffer overflow vulnerability in FFmpeg's minterpolate filter that allows a local attacker to execute arbitrary code via a floating point exception. The vulnerability affects FFmp...

CVE-2023-49501

HIGH CVSS 8.0 Apr 19, 2024

A buffer overflow vulnerability in FFmpeg's config_eq_output function allows local attackers to execute arbitrary code. This affects systems running vulnerable FFmpeg versions where local users can tr...

CVE-2023-49528

HIGH CVSS 8.0 Apr 12, 2024

A buffer overflow vulnerability in FFmpeg's de_stereo component allows local attackers to execute arbitrary code or cause denial of service. This affects FFmpeg version n6.1-3-g466799d4f5 and potentia...

CVE-2024-22861

HIGH CVSS 7.5 Jan 27, 2024

An integer overflow vulnerability in FFmpeg's avcodec/osq module allows attackers to cause denial of service (DoS) by triggering crashes or resource exhaustion. This affects systems running FFmpeg ver...

CVE-2023-47470

HIGH CVSS 7.8 Nov 16, 2023

A buffer overflow vulnerability in FFmpeg's ref_pic_list_struct function allows remote attackers to write outside array bounds, potentially executing arbitrary code or causing denial of service. This ...

CVE-2020-36138

HIGH CVSS 7.5 Aug 11, 2023

This vulnerability in FFmpeg's TIFF decoder allows remote attackers to cause a denial of service by exploiting a NULL pointer dereference. It affects systems using FFmpeg to process TIFF images, poten...

CVE-2022-48434

HIGH CVSS 8.1 Mar 29, 2023

This vulnerability in FFmpeg's libavcodec allows attackers to trigger a use-after-free condition in worker threads when processing certain video files, potentially leading to arbitrary code execution....

CVE-2014-125024

HIGH CVSS 7.3 Jun 19, 2022

This critical vulnerability in FFmpeg 2.0 allows remote attackers to execute arbitrary code or cause denial of service through memory corruption in the lag_decode_frame function. It affects any system...

CVE-2014-125020

HIGH CVSS 7.3 Jun 19, 2022

This critical vulnerability in FFmpeg 2.0 allows remote attackers to trigger memory corruption via the decode_update_thread_context function, potentially leading to arbitrary code execution. It affect...

CVE-2014-125017

HIGH CVSS 7.3 Jun 18, 2022

This critical vulnerability in FFmpeg 2.0 allows remote attackers to cause memory corruption through the rpza_decode_stream function, potentially leading to arbitrary code execution. It affects any sy...

CVE-2014-125015

HIGH CVSS 7.3 Jun 18, 2022

This critical vulnerability in FFmpeg 2.0 allows remote attackers to trigger memory corruption through the read_var_block_data function. Attackers can exploit this to potentially execute arbitrary cod...

CVE-2021-38090

HIGH CVSS 8.8 Sep 20, 2021

This integer overflow vulnerability in FFmpeg's convolution filter allows attackers to cause denial of service or potentially execute arbitrary code by processing specially crafted video files. It aff...

CVE-2021-38092

HIGH CVSS 8.8 Sep 20, 2021

This integer overflow vulnerability in FFmpeg's convolution filter allows attackers to cause denial of service or potentially execute arbitrary code by processing specially crafted video files. It aff...

CVE-2021-38094

HIGH CVSS 8.8 Sep 20, 2021

This integer overflow vulnerability in FFmpeg's filter_sobel function allows attackers to cause denial of service or potentially execute arbitrary code by processing specially crafted video files. It ...

CVE-2020-20896

HIGH CVSS 8.8 Sep 20, 2021

A null pointer dereference vulnerability in FFmpeg's latm_write_packet function allows attackers to cause denial of service or potentially execute arbitrary code by processing malicious media files. T...

CVE-2020-20898

HIGH CVSS 8.8 Sep 20, 2021

An integer overflow vulnerability in FFmpeg's convolution filter allows attackers to cause denial of service or potentially execute arbitrary code by processing specially crafted video files. This aff...

CVE-2020-20892

HIGH CVSS 8.8 Sep 20, 2021

A division by zero vulnerability in FFmpeg's lens correction filter allows attackers to cause denial of service or potentially execute arbitrary code by processing specially crafted video files. This ...

CVE-2020-21688

HIGH CVSS 8.8 Aug 10, 2021

CVE-2020-21688 is a heap-use-after-free vulnerability in FFmpeg's memory management function that allows attackers to execute arbitrary code on affected systems. This affects any application or servic...

CVE-2021-33815

HIGH CVSS 8.8 Jun 3, 2021

This vulnerability in FFmpeg's EXR image decoder allows out-of-bounds array access due to insufficient validation of the dc_count parameter. Attackers can exploit this to potentially execute arbitrary...

CVE-2020-22036

HIGH CVSS 8.8 Jun 1, 2021

This is a heap-based buffer overflow vulnerability in FFmpeg's filter_intra function that could allow attackers to execute arbitrary code or cause denial of service. It affects FFmpeg 4.2 installation...

CVE-2020-22017

HIGH CVSS 8.8 May 27, 2021

This heap-based buffer overflow vulnerability in FFmpeg's drawutils.c allows attackers to corrupt memory by sending specially crafted media files. It affects systems using FFmpeg 4.2 for media process...

CVE-2020-22023

HIGH CVSS 8.8 May 27, 2021

A heap-based buffer overflow vulnerability in FFmpeg's bitplanenoise filter allows attackers to cause memory corruption by processing specially crafted video files. This affects systems using FFmpeg 4...

CVE-2020-22027

HIGH CVSS 8.8 May 27, 2021

A heap-based buffer overflow vulnerability in FFmpeg's neighbor filter allows attackers to execute arbitrary code or cause denial of service by processing specially crafted video files. This affects s...

CVE-2020-22034

HIGH CVSS 8.8 May 27, 2021

A heap-based buffer overflow vulnerability in FFmpeg's floodfill filter allows attackers to execute arbitrary code or cause denial of service by processing specially crafted video files. This affects ...

CVE-2020-22029

HIGH CVSS 8.8 May 27, 2021

This is a heap-based buffer overflow vulnerability in FFmpeg's colorconstancy filter that allows attackers to cause memory corruption by processing specially crafted video files. It affects FFmpeg 4.2...

CVE-2020-22031

HIGH CVSS 8.8 May 27, 2021

A heap-based buffer overflow vulnerability in FFmpeg's w3fdif video filter allows attackers to cause memory corruption by processing specially crafted video files. This affects systems using FFmpeg 4....

CVE-2020-22015

HIGH CVSS 8.8 May 26, 2021

This buffer overflow vulnerability in FFmpeg's MOV file handling allows attackers to execute arbitrary code, cause denial of service, or leak sensitive information by crafting malicious video files. I...

CVE-2020-24020

HIGH CVSS 8.8 May 26, 2021

This CVE describes a buffer overflow vulnerability in FFmpeg's DNN module that allows remote attackers to execute arbitrary code by exploiting improper memory bounds checking in the pad layer function...

CVE-2020-20450

HIGH CVSS 7.5 May 25, 2021

CVE-2020-20450 is a null pointer dereference vulnerability in FFmpeg 4.2's libavformat/aviobuf.c component that can cause a denial of service. Attackers can crash FFmpeg processes by providing special...

CVE-2021-30123

HIGH CVSS 8.8 Apr 7, 2021

CVE-2021-30123 is a buffer overflow vulnerability in FFmpeg's libavcodec library that allows remote attackers to execute arbitrary code by providing a specially crafted media file. This affects all sy...

CVE-2020-24995

HIGH CVSS 7.8 Mar 30, 2021

This CVE describes a buffer overflow vulnerability in the sniff_channel_order function within ffmpeg's AAC decoder. Attackers can exploit this to execute arbitrary code locally on affected systems. Us...

CVE-2025-10256

MEDIUM CVSS 5.3 Feb 18, 2026

A NULL pointer dereference vulnerability in FFmpeg's Firequalizer filter allows attackers to cause denial of service by crashing applications that process malicious media files. This affects any softw...

CVE-2025-22921

MEDIUM CVSS 6.5 Feb 18, 2025

This vulnerability in FFmpeg's JPEG2000 decoder allows attackers to cause a segmentation fault (crash) by processing specially crafted JPEG2000 images. It affects systems using vulnerable FFmpeg versi...

CVE-2025-25469

MEDIUM CVSS 6.5 Feb 18, 2025

A memory leak vulnerability exists in FFmpeg's IAMF (Immersive Audio Model and Format) component that could allow attackers to cause denial of service through resource exhaustion. This affects systems...

CVE-2025-0518

MEDIUM CVSS 5.3 Jan 16, 2025

This CVE describes an unchecked return value and out-of-bounds read vulnerability in FFmpeg's pan audio filter that could allow reading sensitive constants from executable memory. The vulnerability af...

CVE-2023-6601

MEDIUM CVSS 4.7 Jan 6, 2025

This vulnerability in FFmpeg's HLS demuxer allows attackers to bypass file extension checks by using base64-encoded data URIs with specific extensions, potentially triggering arbitrary demuxers. It af...

CVE-2024-36613

MEDIUM CVSS 6.2 Jan 3, 2025

FFmpeg versions containing the vulnerable DXA demuxer in libavformat have an integer overflow vulnerability that can cause denial-of-service (DoS) or undefined behavior when processing malicious DXA v...

CVE-2023-6602

MEDIUM CVSS 5.3 Dec 31, 2024

This vulnerability in FFmpeg's TTY Demuxer allows data exfiltration through improper parsing of non-TTY-compliant input files in HLS playlists. Attackers can craft malicious HLS playlists to potential...

CVE-2024-36615

MEDIUM CVSS 5.9 Nov 29, 2024

FFmpeg n7.0 has a race condition vulnerability in its VP9 decoder where video encoding parameters can be accessed simultaneously by decoder and output threads, causing a data race. This affects any ap...

CVE-2024-36617

MEDIUM CVSS 6.2 Nov 29, 2024

CVE-2024-36617 is an integer overflow vulnerability in FFmpeg's CAF decoder that could allow attackers to cause denial of service or potentially execute arbitrary code by processing specially crafted ...

CVE-2024-36619

MEDIUM CVSS 5.3 Nov 29, 2024

CVE-2024-36619 is an integer overflow vulnerability in FFmpeg's WAVARC decoder that can cause a denial-of-service condition when processing specially crafted WAVARC audio files. This affects any syste...

CVE-2024-7272

MEDIUM CVSS 6.3 Aug 12, 2024

A critical heap-based buffer overflow vulnerability in FFmpeg's fill_audiodata function allows remote attackers to execute arbitrary code or cause denial of service. This affects FFmpeg versions up to...

CVE-2024-7055

MEDIUM CVSS 6.3 Aug 6, 2024

A critical heap-based buffer overflow vulnerability exists in FFmpeg's PNM image decoder (pnm_decode_frame function). Attackers can exploit this remotely by sending specially crafted PNM files, potent...