cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 10 of 19
CVE-2023-51791P4LOWCVSS 7.8fixed in ffmpeg 7:7.0.1-3 (forky)2023
CVE-2023-51791 [HIGH] CVE-2023-51791: ffmpeg - Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local att... Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2023-51794P3HIGHCVSS 7.8fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2023
CVE-2023-51794 [HIGH] CVE-2023-51794: ffmpeg - Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att... Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69. Scope: local bookworm: resolved (fixed in 7:5.1.5-0+deb12u1) bullseye: resolved (fixed in 7:4.3.7-0+deb11u1) forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolved (fixed in 7:7.
debian
CVE-2015-3395P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.6.2-1 (bookworm)2015
CVE-2015-3395 [MEDIUM] CVE-2015-3395: ffmpeg - The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x befor... The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access. Scope: local bookworm: reso
debian
CVE-2023-6603P4HIGHCVSS 7.5fixed in ffmpeg 7:5.0.1-2 (bookworm)2023
CVE-2023-6603 [HIGH] CVE-2023-6603: ffmpeg - A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a d... A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization. Scope: local bookworm: resolved (fixed in 7:5.0.1-2) bullseye: resolved (fixed in 7:4.3.9-0+deb11u2) forky: resolved (fixed in 7:5.0.1-2) sid: resolved (fixed in 7:5.0.1-2
debian
CVE-2020-20896P4HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-20896 [HIGH] CVE-2020-20896: ffmpeg - An issue was discovered in function latm_write_packet in libavformat/latmenc.c i... An issue was discovered in function latm_write_packet in libavformat/latmenc.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a Null pointer dereference. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie
debian
CVE-2020-20892P4HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-20892 [HIGH] CVE-2020-20892: ffmpeg - An issue was discovered in function filter_frame in libavfilter/vf_lenscorrectio... An issue was discovered in function filter_frame in libavfilter/vf_lenscorrection.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a division by zero. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: r
debian
CVE-2011-4364P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-4364 [MEDIUM] CVE-2011-4364: ffmpeg - Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0... Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9 and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VMD file, related to corrupted st
debian
CVE-2014-8545P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.3-1 (bookworm)2014
CVE-2014-8545 [HIGH] CVE-2014-8545: ffmpeg - libavcodec/pngdec.c in FFmpeg before 2.4.2 accepts the monochrome-black format w... libavcodec/pngdec.c in FFmpeg before 2.4.2 accepts the monochrome-black format without verifying that the bits-per-pixel value is 1, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted PNG data. Scope: local bookworm: resolved (fixed in 7:2.4.3-1) bullseye: resolved (fixed in 7:2.4.3-1)
debian
CVE-2014-8546P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.3-1 (bookworm)2014
CVE-2014-8546 [HIGH] CVE-2014-8546: ffmpeg - Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.4.2 allows remote a... Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Cinepak video data. Scope: local bookworm: resolved (fixed in 7:2.4.3-1) bullseye: resolved (fixed in 7:2.4.3-1) forky: resolved (fixed in 7:2.4.3-1) sid: resolved (fixed in 7:
debian
CVE-2014-7933P3HIGHCVSS 7.5fixed in ffmpeg 7:2.5.1-1 (bookworm)2014
CVE-2014-7933 [HIGH] CVE-2014-7933: ffmpeg - Use-after-free vulnerability in the matroska_read_seek function in libavformat/m... Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska file that triggers improper maintenance of tracks data. Scope: local bookworm: resolved (f
debian
CVE-2012-0858P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.2.1-1 (bookworm)2012
CVE-2012-0858 [MEDIUM] CVE-2012-0858: ffmpeg - The Shorten codec (shorten.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.... The Shorten codec (shorten.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Shorten file, related to an "invalid free". Scope:
debian
CVE-2015-8216P4HIGHCVSS 7.5fixed in ffmpeg 7:2.8.2-1 (bookworm)2015
CVE-2015-8216 [HIGH] CVE-2015-8216: ffmpeg - The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8... The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG data. Scope: local bookworm: resolved (fixed in 7:2.8.2-1) bullseye: resolved (fixed in 7:2.8.2-1) fo
debian
CVE-2015-6824P4HIGHCVSS 7.5fixed in ffmpeg 7:2.7.2-1 (bookworm)2015
CVE-2015-6824 [HIGH] CVE-2015-6824: ffmpeg - The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does ... The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact via crafted video data. Scope: local bookworm: resolved (fixed in 7:2.7.2-1) bullseye: resolved (fixed in 7:2.7.2-1) f
debian
CVE-2014-9317P4HIGHCVSS 7.5fixed in ffmpeg 2.4.4-1 (bookworm)2014
CVE-2014-9317 [HIGH] CVE-2014-9317: ffmpeg - The decode_ihdr_chunk function in libavcodec/pngdec.c in FFMpeg before 2.1.6, 2.... The decode_ihdr_chunk function in libavcodec/pngdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via an IDAT before an IHDR in a PNG file. Scope: local bookworm: resolved (fixed in 2.4.4-1) bullseye: resolved (fixed in 2.4
debian
CVE-2014-9604P4HIGHCVSS 7.5fixed in ffmpeg 7:2.5.1-1 (bookworm)2014
CVE-2014-9604 [HIGH] CVE-2014-9604: ffmpeg - libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value o... libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video data, related to the (1) restore_median and (2) restore_median_il functions. Scope: local bookworm: resolved (fixed in 7:2
debian
CVE-2016-7502P4HIGHCVSS 7.8fixed in ffmpeg 7:3.1.4-1 (bookworm)2016
CVE-2016-7502 [HIGH] CVE-2016-7502: ffmpeg - The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is ... The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode. Scope: local bookworm: resolved (fixed in 7:3.1.4-1) bullseye: resolved (fixed in 7:3.1.4-1) forky: resolved (fixed in 7:3.1.4-1) sid: resolved (fixed in 7:3.1.4-1) trixie: resolved (fixed in 7:3.1.4-1)
debian
CVE-2011-3895P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3895 [HIGH] CVE-2011-3895: ffmpeg - Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.87... Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) tri
debian
CVE-2014-9602P4HIGHCVSS 7.5fixed in ffmpeg 7:2.5.1-1 (bookworm)2014
CVE-2014-9602 [HIGH] CVE-2014-9602: ffmpeg - libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words a... libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relationship, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted X-Face image data. Scope: local bookworm: resolved (fixed in 7:2.5.1-1) bul
debian
CVE-2014-7937P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.2-1 (bookworm)2014
CVE-2014-7937 [HIGH] CVE-2014-7937: ffmpeg - Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as ... Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Vorbis I data. Scope: local bookworm: resolved (fixed in 7:2.4.2-1) bullseye: resolved (fixed in 7:2.4.2-1) forky: resolved (
debian
CVE-2024-31582P4HIGHCVSS 7.8fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2024
CVE-2024-31582 [HIGH] CVE-2024-31582: ffmpeg - FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerabili... FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input. Scope: local bookworm: resolved (fixed in 7:5.1.7-0+deb12u1) bullseye: resolved forky: resolved (fixed in
debian
Debian Ffmpeg vulnerabilities | cvebase