cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 12 of 19
CVE-2014-9316P4HIGHCVSS 7.5fixed in ffmpeg 2.4.4-1 (bookworm)2014
CVE-2014-9316 [HIGH] CVE-2014-9316: ffmpeg - The mjpeg_decode_app function in libavcodec/mjpegdec.c in FFMpeg before 2.1.6, 2... The mjpeg_decode_app function in libavcodec/mjpegdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via vectors related to LJIF tags in an MJPEG file. Scope: local bookworm: resolved (fixed in 2.4.4-1) bullseye: resolved (fi
debian
CVE-2014-5272P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2014
CVE-2014-5272 [MEDIUM] CVE-2014-5272: ffmpeg - libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7... libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote attackers to have unspecified impact via a crafted iff image, which triggers an out-of-bounds array access, related to the rgb8 and rgbn formats. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: reso
debian
CVE-2023-51797P4LOWCVSS 6.7fixed in ffmpeg 7:7.0.1-3 (forky)2023
CVE-2023-51797 [MEDIUM] CVE-2023-51797: ffmpeg - Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att... Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2011-0723P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-0723 [MEDIUM] CVE-2011-0723: ffmpeg - FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to ... FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed VC-1 file. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved
debian
CVE-2011-0722P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-0722 [MEDIUM] CVE-2011-0722: ffmpeg - FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attack... FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a malformed RealMedia file. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolve
debian
CVE-2017-11665P4HIGHCVSS 7.5fixed in ffmpeg 7:3.3.3-1 (bookworm)2017
CVE-2017-11665 [HIGH] CVE-2017-11665: ffmpeg - The ff_amf_get_field_value function in libavformat/rtmppkt.c in FFmpeg 3.3.2 all... The ff_amf_get_field_value function in libavformat/rtmppkt.c in FFmpeg 3.3.2 allows remote RTMP servers to cause a denial of service (Segmentation Violation and application crash) via a crafted stream. Scope: local bookworm: resolved (fixed in 7:3.3.3-1) bullseye: resolved (fixed in 7:3.3.3-1) forky: resolved (fixed in 7:3.3.3-1) sid: resolved (fixed in 7:3.3.3-1) tr
debian
CVE-2011-3952P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3952 [MEDIUM] CVE-2011-3952: ffmpeg - The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Li... The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large palette size in a KMVC encoded file. Scope: local bookworm: resolved (fixed in 7:
debian
CVE-2012-0852P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-0852 [MEDIUM] CVE-2012-0852: ffmpeg - The adpcm_decode_frame function in adpcm.c in libavcodec in FFmpeg before 0.9.1 ... The adpcm_decode_frame function in adpcm.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an ADPCM file with the number of channels not equal to two. Scope: local bookwor
debian
CVE-2014-2263P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2014
CVE-2014-2263 [MEDIUM] CVE-2014-2263: ffmpeg - The mpegts_write_pmt function in the MPEG2 transport stream (aka DVB) muxer (lib... The mpegts_write_pmt function in the MPEG2 transport stream (aka DVB) muxer (libavformat/mpegtsenc.c) in FFmpeg, possibly 2.1 and earlier, allows remote attackers to have unspecified impact and vectors, which trigger an out-of-bounds write. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1
debian
CVE-2015-8365P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.8.3-1 (bookworm)2015
CVE-2015-8365 [MEDIUM] CVE-2015-8365: ffmpeg - The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2... The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Smacker data. Scope: local
debian
CVE-2018-1999012P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-1999012 [MEDIUM] CVE-2018-1999012: ffmpeg - FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835... FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in a Vulnerability that allows attackers to consume excessive amount of resources like CPU and RAM. This attack appear to be exploitable via specially crafted PVA file has to be provided as input. This vulnerability
debian
CVE-2018-1999014P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-1999014 [MEDIUM] CVE-2018-1999014: ffmpeg - FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of... FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which has to be provided as input. This vulnerability appears to have been fixed in bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 and later. Scope
debian
CVE-2012-0859P4MEDIUMCVSS 5.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-0859 [MEDIUM] CVE-2012-0859: ffmpeg - The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg ... The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Vorbis file, related to a large multiplier. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3893. Scope: local bookworm: resolv
debian
CVE-2017-11399P4HIGHCVSS 7.8fixed in ffmpeg 7:3.3.3-1 (bookworm)2017
CVE-2017-11399 [HIGH] CVE-2017-11399: ffmpeg - Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmp... Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg 2.4 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access and application crash) or possibly have unspecified other impact via a crafted APE file. Scope: local bookworm: resolved (fixed in 7:3.3.3-1) bullseye: resolved (fixed in 7:3.3.3-1) forky: resol
debian
CVE-2011-3892P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3892 [HIGH] CVE-2011-3892: ffmpeg - Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874... Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trix
debian
CVE-2013-2496P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-2496 [HIGH] CVE-2013-2496: ffmpeg - The msrle_decode_8_16_24_32 function in msrledec.c in libavcodec in FFmpeg throu... The msrle_decode_8_16_24_32 function in msrledec.c in libavcodec in FFmpeg through 1.1.3 does not properly determine certain end pointers, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted Microsoft RLE data. Scope: local bookworm: resolved (fixed in 7:2.4.
debian
CVE-2013-2495P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-2495 [HIGH] CVE-2013-2495: ffmpeg - The iff_read_header function in iff.c in libavformat in FFmpeg through 1.1.3 doe... The iff_read_header function in iff.c in libavformat in FFmpeg through 1.1.3 does not properly handle data sizes for Interchange File Format (IFF) data during operations involving a CMAP chunk or a video codec, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) or possibly have unspecified ot
debian
CVE-2010-3908P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2010
CVE-2010-3908 [MEDIUM] CVE-2010-3908: ffmpeg - FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attack... FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed WMV file. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in
debian
CVE-2012-5150P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-5150 [HIGH] CVE-2012-5150: ffmpeg - Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote ... Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving seek operations on video data. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2
debian
CVE-2013-7015P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-7015 [MEDIUM] CVE-2013-7015: ffmpeg - The flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before 2.1 d... The flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before 2.1 does not properly validate a certain height value, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Flash Screen Video data. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved
debian
Debian Ffmpeg vulnerabilities | cvebase