cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 1 of 19
CVE-2009-4637P2CRITICALCVSS 10.0PoCfixed in ffmpeg 4:0.5+svn20090706-3 (bookworm)2009
CVE-2009-4637 [CRITICAL] CVE-2009-4637: ffmpeg - FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and poss... FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow. Scope: local bookworm: resolved (fixed in 4:0.5+svn20090706-3) bullseye: resolved (fixed in 4:0.5+svn20090706-3) forky: resolved (fixed in 4:0.5+svn20090706-3) sid: resolved (fixed in 4:0.5+svn20
debian
CVE-2008-3162P3CRITICALCVSS 9.3PoCfixed in ffmpeg 0.svn20080206-10 (bookworm)2008
CVE-2008-3162 [CRITICAL] CVE-2008-3162: ffmpeg - Stack-based buffer overflow in the str_read_packet function in libavformat/psxst... Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted STR file that interleaves audio and video sectors. Scope: local bookworm: resolved (fixed in 0.svn20080206-10) bullseye: resolved (fixed in 0.svn2
debian
CVE-2016-10190P3CRITICALCVSS 9.8fixed in ffmpeg 7:3.2.2-1 (bookworm)2016
CVE-2016-10190 [CRITICAL] CVE-2016-10190: ffmpeg - Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x ... Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response. Scope: local bookworm: resolved (fixed in 7:3.2.2-1) bullseye: resolved (fixed in 7:3.2.2-1) forky: resolved (fixed in 7:3.2.2-1)
debian
CVE-2016-10191P3CRITICALCVSS 9.8fixed in ffmpeg 7:3.2.2-1 (bookworm)2016
CVE-2016-10191 [CRITICAL] CVE-2016-10191: ffmpeg - Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0... Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches. Scope: local bookworm: resolved (fixed in 7:3.2.2-1) bullseye: resolved (fixed in 7:3.2.2-1) forky: resolved (f
debian
CVE-2017-9993P3HIGHCVSS 7.5fixed in ffmpeg 7:3.2.6-1 (bookworm)2017
CVE-2017-9993 [HIGH] CVE-2017-9993: ffmpeg - FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.... FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data. Scope: local bookworm: resolved (fixed in 7:3.2.6-1) bullseye: resolved (fixed in 7:3.2.6-1) forky: resolved (fixed
debian
CVE-2025-1594P3MEDIUMCVSS 5.3fixed in ffmpeg 7:5.1.8-0+deb12u1 (bookworm)2025
CVE-2025-1594 [MEDIUM] CVE-2025-1594: ffmpeg - A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1... A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Scope: l
debian
CVE-2016-10192P3CRITICALCVSS 9.8fixed in ffmpeg 7:3.2.2-1 (bookworm)2016
CVE-2016-10192 [CRITICAL] CVE-2016-10192: ffmpeg - Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3... Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size. Scope: local bookworm: resolved (fixed in 7:3.2.2-1) bullseye: resolved (fixed in 7:3.2.2-1) forky: resolved (fixed in 7:3.2.2-1) sid: resolved
debian
CVE-2018-1999010P3CRITICALCVSS 9.8fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-1999010 [CRITICAL] CVE-2018-1999010: ffmpeg - FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple ... FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in cced03dd667a5df6df8fd40d8de0bff477ee02e8 and later. Sco
debian
CVE-2024-22862P3LOWCVSS 9.8fixed in ffmpeg 7:6.1-1 (forky)2024
CVE-2024-22862 [CRITICAL] CVE-2024-22862: ffmpeg - Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to... Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 7:6.1-1) sid: resolved (fixed in 7:6.1-1) trixie: resolved (fixed in 7:6.1-1)
debian
CVE-2024-7272P3MEDIUMCVSS 6.9fixed in ffmpeg 7:5.1.6-0+deb12u1 (bookworm)2024
CVE-2024-7272 [MEDIUM] CVE-2024-7272: ffmpeg - A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1... A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audiodata of the file /libswresample/swresample.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. This issue was fixed in version 6.0 by 9903ba28c28ab18dc7b7b6fb8571cc8b5caae1a6 but a backport for 5.
debian
CVE-2024-7055P3MEDIUMCVSS 6.9fixed in ffmpeg 7:5.1.6-0+deb12u1 (bookworm)2024
CVE-2024-7055 [MEDIUM] CVE-2024-7055: ffmpeg - A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as criti... A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to ad
debian
CVE-2020-12284P3CRITICALCVSS 9.8fixed in ffmpeg 7:4.2.3-1 (bookworm)2020
CVE-2020-12284 [CRITICAL] CVE-2020-12284: ffmpeg - cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a h... cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check. Scope: local bookworm: resolved (fixed in 7:4.2.3-1) bullseye: resolved (fixed in 7:4.2.3-1) forky: resolved (fixed in 7:4.2.3-1) sid: resolved (fixed in 7:4.2.3-1) trixie: resolved (fixed in
debian
CVE-2024-22860P3LOWCVSS 9.8fixed in ffmpeg 7:6.1-1 (forky)2024
CVE-2024-22860 [CRITICAL] CVE-2024-22860: ffmpeg - Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to... Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the jpegxl_anim_read_packet component in the JPEG XL Animation decoder. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 7:6.1-1) sid: resolved (fixed in 7:6.1-1) trixie: resolved (fixed in 7:6.1-1)
debian
CVE-2014-4610P3HIGHCVSS 8.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2014
CVE-2014-4610 [HIGH] CVE-2014-4610: ffmpeg - Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.1... Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: reso
debian
CVE-2017-7866P3CRITICALCVSS 9.8fixed in ffmpeg 7:3.2.4-1 (bookworm)2017
CVE-2017-7866 [CRITICAL] CVE-2017-7866: ffmpeg - FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buff... FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c. Scope: local bookworm: resolved (fixed in 7:3.2.4-1) bullseye: resolved (fixed in 7:3.2.4-1) forky: resolved (fixed in 7:3.2.4-1) sid: resolved (fixed in 7:3.2.4-1) trixie: resolved (fixed in 7:3.2.4-1)
debian
CVE-2018-1999011P3HIGHCVSS 8.8fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-1999011 [HIGH] CVE-2018-1999011: ffmpeg - FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer ... FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow vulnerability in asf_o format demuxer that can result in heap-buffer-overflow that may result in remote code execution. This attack appears to be exploitable via specially crafted ASF file that has to be provided as input to FFmpeg. This vulnerability appears to have been fix
debian
CVE-2009-4635P3CRITICALCVSS 9.3fixed in ffmpeg 4:0.5+svn20090706-3 (bookworm)2009
CVE-2009-4635 [CRITICAL] CVE-2009-4635: ffmpeg - FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly exe... FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted MOV container with improperly ordered tags that cause (1) mov.c and (2) utils.c to use inconsistent codec types and identifiers, leading to processing of a video-structure pointer by the mp3 decoder, and a stack-based buffer overflow. Scope: local bookw
debian
CVE-2017-7865P3CRITICALCVSS 9.8fixed in ffmpeg 7:3.2.4-1 (bookworm)2017
CVE-2017-7865 [CRITICAL] CVE-2017-7865: ffmpeg - FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffe... FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c. Scope: local bookworm: resolved (fixed in 7:3.2.4-1) bullseye: resolved (fixed in 7:3.2.4-1) forky: resolved (fixed in 7:3.
debian
CVE-2017-7862P3CRITICALCVSS 9.8fixed in ffmpeg 7:3.2.4-1 (bookworm)2017
CVE-2017-7862 [CRITICAL] CVE-2017-7862: ffmpeg - FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffe... FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c. Scope: local bookworm: resolved (fixed in 7:3.2.4-1) bullseye: resolved (fixed in 7:3.2.4-1) forky: resolved (fixed in 7:3.2.4-1) sid: resolved (fixed in 7:3.2.4-1) trixie: resolved (fixed in 7:3.2.4-1)
debian
CVE-2012-5359P3HIGHCVSS 8.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-5359 [HIGH] CVE-2012-5359: ffmpeg - Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary co... Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted ASF file. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved (fixed in 7:2.4.1-1)
debian
1 / 19Next →
Debian Ffmpeg vulnerabilities | cvebase