cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 13 of 19
CVE-2015-1872P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.5.4-1 (bookworm)2015
CVE-2015-1872 [MEDIUM] CVE-2015-1872: ffmpeg - The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4... The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of components in a JPEG-LS Start Of Frame segment, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Motion JPEG data. Scope: local bookworm: resolved (fixed in 7:2.5.
debian
CVE-2015-8218P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.8.2-1 (bookworm)2015
CVE-2015-8218 [MEDIUM] CVE-2015-8218: ffmpeg - The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2... The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data. Scope: local bookworm: resolved (fixed in 7:2.8.2-1) bullseye: resolved (fixed in 7:2.8.2-1)
debian
CVE-2013-7009P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-7009 [MEDIUM] CVE-2013-7009: ffmpeg - The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does n... The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Apple RPZA data. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:
debian
CVE-2020-20453P4LOWCVSS 6.5fixed in ffmpeg 7:4.4.1-1 (bookworm)2020
CVE-2020-20453 [MEDIUM] CVE-2020-20453: ffmpeg - FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aaccoder, which ... FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aaccoder, which allows a remote malicious user to cause a Denial of Service Scope: local bookworm: resolved (fixed in 7:4.4.1-1) bullseye: resolved (fixed in 7:4.3.3-0+deb11u1) forky: resolved (fixed in 7:4.4.1-1) sid: resolved (fixed in 7:4.4.1-1) trixie: resolved (fixed in 7:4.4.1-1)
debian
CVE-2020-20446P4LOWCVSS 6.5fixed in ffmpeg 7:4.4.1-1 (bookworm)2020
CVE-2020-20446 [MEDIUM] CVE-2020-20446: ffmpeg - FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aacpsy.c, which ... FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aacpsy.c, which allows a remote malicious user to cause a Denial of Service. Scope: local bookworm: resolved (fixed in 7:4.4.1-1) bullseye: resolved (fixed in 7:4.3.3-0+deb11u1) forky: resolved (fixed in 7:4.4.1-1) sid: resolved (fixed in 7:4.4.1-1) trixie: resolved (fixed in 7:4.4.1-1)
debian
CVE-2020-20445P4LOWCVSS 6.5fixed in ffmpeg 7:5.0.1-2 (bookworm)2020
CVE-2020-20445 [MEDIUM] CVE-2020-20445: ffmpeg - FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/lpc.h, which all... FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/lpc.h, which allows a remote malicious user to cause a Denial of Service. Scope: local bookworm: resolved (fixed in 7:5.0.1-2) bullseye: resolved (fixed in 7:4.3.3-0+deb11u1) forky: resolved (fixed in 7:5.0.1-2) sid: resolved (fixed in 7:5.0.1-2) trixie: resolved (fixed in 7:5.0.1-2)
debian
CVE-2020-35964P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.3.1-6 (bookworm)2020
CVE-2020-35964 [MEDIUM] CVE-2020-35964: ffmpeg - track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write... track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing. Scope: local bookworm: resolved (fixed in 7:4.3.1-6) bullseye: resolved (fixed in 7:4.3.1-6) forky: resolved (fixed in 7:4.3.1-6) sid: resolved (fixed in 7:4.3.1-6) trixie: resolved (fixed in 7:4.3.1-6)
debian
CVE-2020-20902P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.2.2-1 (bookworm)2020
CVE-2020-20902 [MEDIUM] CVE-2020-20902: ffmpeg - A CWE-125: Out-of-bounds read vulnerability exists in long_term_filter function ... A CWE-125: Out-of-bounds read vulnerability exists in long_term_filter function in g729postfilter.c in FFmpeg 4.2.1 during computation of the denominator of pseudo-normalized correlation R'(0), that could result in disclosure of information. Scope: local bookworm: resolved (fixed in 7:4.2.2-1) bullseye: resolved (fixed in 7:4.2.2-1) forky: resolved (fixed in 7:4.2.
debian
CVE-2024-36615P4MEDIUMCVSS 5.9fixed in ffmpeg 7:4.3.9-0+deb11u2 (bullseye)2024
CVE-2024-36615 [MEDIUM] CVE-2024-36615: ffmpeg - FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could le... FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread. Scope: local bookworm: open bullseye: resolved (fixed in 7:4.3.9-0+deb11u2) forky: resolved (fixed in 7:7.1-3) sid: resolve
debian
CVE-2017-9608P4MEDIUMCVSS 6.5fixed in ffmpeg 7:3.3.3-1 (bookworm)2017
CVE-2017-9608 [MEDIUM] CVE-2017-9608: ffmpeg - The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote a... The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file. Scope: local bookworm: resolved (fixed in 7:3.3.3-1) bullseye: resolved (fixed in 7:3.3.3-1) forky: resolved (fixed in 7:3.3.3-1) sid: resolved (fixed in 7:3.3.3-1) trixie: resolved (fixed in 7:3.3.3-
debian
CVE-2011-3940P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3940 [MEDIUM] CVE-2011-3940: ffmpeg - nsvdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, an... nsvdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted NSV file that triggers "use of uninitialized streams." Scope: local bookworm: resolved (fixed in
debian
CVE-2015-3417P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.6.1-1 (bookworm)2015
CVE-2015-3417 [MEDIUM] CVE-2015-3417: ffmpeg - Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h... Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data. Scope: local bookworm: resolved (fixed in 7:2.6.1-1) bull
debian
CVE-2015-8364P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.8.3-1 (bookworm)2015
CVE-2015-8364 [MEDIUM] CVE-2015-8364: ffmpeg - Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpe... Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data. Scope: local bookworm: resolved (fixe
debian
CVE-2015-8363P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.8.3-1 (bookworm)2015
CVE-2015-8363 [MEDIUM] CVE-2015-8363: ffmpeg - The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg be... The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not enforce uniqueness of the SIZ marker in a JPEG 2000 image, which allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via a crafted image with two
debian
CVE-2013-7020P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-7020 [MEDIUM] CVE-2013-7020: ffmpeg - The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not p... The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted FFV1 data. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (f
debian
CVE-2013-7011P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-7011 [MEDIUM] CVE-2013-7011: ffmpeg - The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not p... The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not prevent changes to global parameters, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted FFV1 data. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky:
debian
CVE-2017-14059P4LOWCVSS 6.5fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14059 [MEDIUM] CVE-2017-14059: ffmpeg - In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might c... In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. When a crafted CINE file, which claims a large "duration" field in the header but does not contain sufficient backing data, is provided, the image-offset parsing loop would consume huge CPU and memory resources, since there is no EOF check inside th
debian
CVE-2017-14170P4LOWCVSS 6.5fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14170 [MEDIUM] CVE-2017-14170: ffmpeg - In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_ar... In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims a large "nb_index_entries" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU resources, since there is no
debian
CVE-2024-32228P4LOWCVSS 6.6fixed in ffmpeg 7:7.0.1-3 (forky)2024
CVE-2024-32228 [MEDIUM] CVE-2024-32228: ffmpeg - FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcd... FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2025-69693P4LOWCVSS 5.4fixed in ffmpeg 7:8.1-1 (forky)2025
CVE-2025-69693 [MEDIUM] CVE-2025-69693: ffmpeg - Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60de... Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid i
debian
Debian Ffmpeg vulnerabilities | cvebase