Vulnerabilities > Ffmpeg

DATE CVE VULNERABILITY TITLE RISK
2023-08-11 CVE-2020-36138 NULL Pointer Dereference vulnerability in Ffmpeg 4.3
An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).
network
low complexity
ffmpeg CWE-476
7.5
2023-08-11 CVE-2021-28429 Integer Overflow or Wraparound vulnerability in Ffmpeg 4.3.2
Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial of service (DoS) via crafted .mov file.
local
low complexity
ffmpeg CWE-190
5.5
2023-03-29 CVE-2022-48434 Use After Free vulnerability in Ffmpeg
libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).
network
high complexity
ffmpeg CWE-416
8.1
2023-01-12 CVE-2022-3341 NULL Pointer Dereference vulnerability in Ffmpeg
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file.
network
low complexity
ffmpeg CWE-476
5.3
2022-12-16 CVE-2022-3109 NULL Pointer Dereference vulnerability in Ffmpeg
An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
network
low complexity
ffmpeg CWE-476
7.5
2022-11-13 CVE-2022-3964 Unspecified vulnerability in Ffmpeg
A vulnerability classified as problematic has been found in ffmpeg.
network
low complexity
ffmpeg
8.1
2022-11-13 CVE-2022-3965 Unspecified vulnerability in Ffmpeg
A vulnerability classified as problematic was found in ffmpeg.
network
low complexity
ffmpeg
8.1
2022-09-23 CVE-2022-2566 Integer Overflow or Wraparound vulnerability in Ffmpeg 5.1
A heap out-of-bounds memory write exists in FFMPEG since version 5.1.
local
low complexity
ffmpeg CWE-190
7.8
2022-06-19 CVE-2014-125018 Out-of-bounds Write vulnerability in Ffmpeg 2.0
A vulnerability, which was classified as problematic, has been found in FFmpeg 2.0.
local
low complexity
ffmpeg CWE-787
5.5
2022-06-19 CVE-2014-125019 Out-of-bounds Write vulnerability in Ffmpeg 2.0
A vulnerability, which was classified as problematic, was found in FFmpeg 2.0.
local
low complexity
ffmpeg CWE-787
5.5