Debian Ffmpeg vulnerabilities
375 known vulnerabilities affecting debian/ffmpeg.
Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80
Vulnerabilities
Page 11 of 19
CVE-2020-20450P4LOWCVSS 7.5fixed in ffmpeg 7:4.4-5 (bookworm)2020
CVE-2020-20450 [HIGH] CVE-2020-20450: ffmpeg - FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavfo...
FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavformat/aviobuf.c, which could cause a Denial of Service.
Scope: local
bookworm: resolved (fixed in 7:4.4-5)
bullseye: resolved (fixed in 7:4.3.3-0+deb11u1)
forky: resolved (fixed in 7:4.4-5)
sid: resolved (fixed in 7:4.4-5)
trixie: resolved (fixed in 7:4.4-5)
debian
CVE-2011-0480P4CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-0480 [CRITICAL] CVE-2011-0480: ffmpeg - Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as us...
Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2)
debian
CVE-2011-3944P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3944 [MEDIUM] CVE-2011-3944: ffmpeg - The smacker_decode_header_tree function in libavcodec/smacker.c in FFmpeg before...
The smacker_decode_header_tree function in libavcodec/smacker.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Smacker data.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
debian
CVE-2011-3934P4LOWCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3934 [MEDIUM] CVE-2011-3934: ffmpeg - Double free vulnerability in the vp3_update_thread_context function in libavcode...
Double free vulnerability in the vp3_update_thread_context function in libavcodec/vp3.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted vp3 data.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (
debian
CVE-2018-1999013P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-1999013 [MEDIUM] CVE-2018-1999013: ffmpeg - FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-aft...
FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a27745236677195
debian
CVE-2018-1999015P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-1999015 [MEDIUM] CVE-2018-1999015: ffmpeg - FFmpeg before commit 5aba5b89d0b1d73164d3b81764828bb8b20ff32a contains an out of...
FFmpeg before commit 5aba5b89d0b1d73164d3b81764828bb8b20ff32a contains an out of array read vulnerability in ASF_F format demuxer that can result in heap memory reading. This attack appear to be exploitable via specially crafted ASF file that has to provided as input. This vulnerability appears to have been fixed in 5aba5b89d0b1d73164d3b81764828bb8b20ff32a and
debian
CVE-2008-4868P4LOWCVSS 10.0fixed in mplayer 1.0~rc2-14 (bookworm)2008
CVE-2008-4868 [CRITICAL] CVE-2008-4868: ffmpeg - Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in...
Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer, has unknown impact and attack vectors, related to a free "on random pointers."
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2017-11719P4HIGHCVSS 7.8fixed in ffmpeg 7:3.3.3-1 (bookworm)2017
CVE-2017-11719 [HIGH] CVE-2017-11719: ffmpeg - The dnxhd_decode_header function in libavcodec/dnxhddec.c in FFmpeg 3.0 through ...
The dnxhd_decode_header function in libavcodec/dnxhddec.c in FFmpeg 3.0 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a crafted DNxHD file.
Scope: local
bookworm: resolved (fixed in 7:3.3.3-1)
bullseye: resolved (fixed in 7:3.3.3-1)
forky: resolved (fixed in 7:3.3.3-1)
sid: resol
debian
CVE-2015-6819P4HIGHCVSS 7.5fixed in ffmpeg 7:2.7.2-1 (bookworm)2015
CVE-2015-6819 [HIGH] CVE-2015-6819: ffmpeg - Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/...
Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG data.
Scope: local
bookworm: resolved (fixed in 7:2.7.2-1)
bullseye: resolved (fixed in 7:2.7.2-1)
forky: resolved (
debian
CVE-2015-6822P4HIGHCVSS 7.5fixed in ffmpeg 7:2.7.2-1 (bookworm)2015
CVE-2015-6822 [HIGH] CVE-2015-6822: ffmpeg - The destroy_buffers function in libavcodec/sanm.c in FFmpeg before 2.7.2 does no...
The destroy_buffers function in libavcodec/sanm.c in FFmpeg before 2.7.2 does not properly maintain height and width values in the video context, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via crafted LucasArts Smush video data.
Scope: local
bookworm: resolved (fixe
debian
CVE-2013-2277P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-2277 [HIGH] CVE-2013-2277: ffmpeg - The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmp...
The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 1.1.3 does not validate the relationship between luma depth and chroma depth, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted H.264 data.
Scope: local
bookworm: reso
debian
CVE-2016-7450P4HIGHCVSS 7.8fixed in ffmpeg 7:3.1.4-1 (bookworm)2016
CVE-2016-7450 [HIGH] CVE-2016-7450: ffmpeg - The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vu...
The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed AIFF file.
Scope: local
bookworm: resolved (fixed in 7:3.1.4-1)
bullseye: resolved (fixed in 7:3.1.4-1)
forky: resolved (fixed in 7:3.1.4-1)
sid: resolved (fixed in 7:3.1.4-1)
trixie: resolved (fixed in 7:3.1.4-1)
debian
CVE-2013-0894P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0894 [HIGH] CVE-2013-0894: ffmpeg - Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis deco...
Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds array access) or po
debian
CVE-2011-3362P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3362 [MEDIUM] CVE-2011-3362: ffmpeg - Integer signedness error in the decode_residual_block function in cavsdec.c in l...
Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through 0.7.1, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.
Scope: local
bookworm: resol
debian
CVE-2012-0851P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-0851 [MEDIUM] CVE-2012-0851: ffmpeg - The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmp...
The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted H.264 file, related to the chroma_format_idc value.
Sc
debian
CVE-2011-3951P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3951 [MEDIUM] CVE-2011-3951: ffmpeg - The dpcm_decode_frame function in dpcm.c in libavcodec in FFmpeg before 0.10 and...
The dpcm_decode_frame function in dpcm.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted stereo stream in a media file.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2024-22861P4LOWCVSS 7.5fixed in ffmpeg 7:6.1-1 (forky)2024
CVE-2024-22861 [HIGH] CVE-2024-22861: ffmpeg - Integer overflow vulnerability in FFmpeg before n6.1, allows attackers to cause ...
Integer overflow vulnerability in FFmpeg before n6.1, allows attackers to cause a denial of service (DoS) via the avcodec/osq module.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 7:6.1-1)
sid: resolved (fixed in 7:6.1-1)
trixie: resolved (fixed in 7:6.1-1)
debian
CVE-2014-8542P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.3-1 (bookworm)2014
CVE-2014-8542 [HIGH] CVE-2014-8542: ffmpeg - libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforc...
libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data.
Scope: local
bookworm: resolved (fixed in 7:2.4.3-1)
bullseye: resolved (fixed in 7:2.4.3-1)
forky: resolved (fixed in 7:2.4.3
debian
CVE-2015-6825P4HIGHCVSS 7.5fixed in ffmpeg 7:2.7.2-1 (bookworm)2015
CVE-2015-6825 [HIGH] CVE-2015-6825: ffmpeg - The ff_frame_thread_init function in libavcodec/pthread_frame.c in FFmpeg before...
The ff_frame_thread_init function in libavcodec/pthread_frame.c in FFmpeg before 2.7.2 mishandles certain memory-allocation failures, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via a crafted file, as demonstrated by an AVI file.
Scope: local
bookworm: resolved (fixed in 7:2.7.2-1)
bullse
debian
CVE-2014-8548P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.3-1 (bookworm)2014
CVE-2014-8548 [HIGH] CVE-2014-8548: ffmpeg - Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attack...
Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime Graphics (aka SMC) video data.
Scope: local
bookworm: resolved (fixed in 7:2.4.3-1)
bullseye: resolved (fixed in 7:2.4.3-1)
forky: resolved (fixed in 7:2.4.3-1)
sid: resol
debian