Vulnerabilities > Ffmpeg > Ffmpeg > 4.4

DATE CVE VULNERABILITY TITLE RISK
2021-08-21 CVE-2021-38171 Unchecked Return Value vulnerability in multiple products
adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted.
network
low complexity
ffmpeg debian CWE-252
critical
9.8
2021-08-04 CVE-2021-38114 Unchecked Return Value vulnerability in multiple products
libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a similar issue to CVE-2013-0868.
local
low complexity
ffmpeg debian CWE-252
5.5
2021-06-03 CVE-2021-33815 Improper Validation of Array Index vulnerability in Ffmpeg 4.4
dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an out-of-bounds array access because dc_count is not strictly checked.
network
low complexity
ffmpeg CWE-129
8.8
2021-04-07 CVE-2021-30123 Classic Buffer Overflow vulnerability in Ffmpeg 4.4
FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code execution.
network
low complexity
ffmpeg CWE-120
8.8