cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 14 of 19
CVE-2017-14223P4LOWCVSS 6.5fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14223 [MEDIUM] CVE-2017-14223: ffmpeg - In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due... In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, which claims a large "ict" field in the header but does not contain sufficient backing data, is provided, the for loop would consume huge CPU and memory resources, since there is no EOF che
debian
CVE-2017-14222P4LOWCVSS 6.5fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14222 [MEDIUM] CVE-2017-14222: ffmpeg - In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF... In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which claims a large "item_count" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU and memory resources, since there is no EOF check i
debian
CVE-2017-14058P4LOWCVSS 6.5fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14058 [MEDIUM] CVE-2017-14058: ffmpeg - In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not re... In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote attackers to cause a denial of service (infinite loop). Scope: local bookworm: resolved (fixed in 7:3.3.4-1) bullseye: resolved (fixed in 7:3.3.4-1) forky: resolved (fixed in 7:3.3.4-1) sid: resolved (fixed in 7:3.3.4-
debian
CVE-2016-2213P4MEDIUMCVSS 6.5fixed in ffmpeg 7:2.8.6-1 (bookworm)2016
CVE-2016-2213 [MEDIUM] CVE-2016-2213: ffmpeg - The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2... The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a denial of service (out-of-bounds array read access) via crafted JPEG 2000 data. Scope: local bookworm: resolved (fixed in 7:2.8.6-1) bullseye: resolved (fixed in 7:2.8.6-1) forky: resolved (fixed in 7:2.8.6-1) sid: resolved (fixed in 7:2.8.6-1) trix
debian
CVE-2017-14056P4LOWCVSS 6.5fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14056 [MEDIUM] CVE-2017-14056: ffmpeg - In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of ... In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted RL2 file, which claims a large "frame_count" field in the header but does not contain sufficient backing data, is provided, the loops (for offset and size tables) would consume huge CPU and memory res
debian
CVE-2017-14055P4LOWCVSS 6.5fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14055 [MEDIUM] CVE-2017-14055: ffmpeg - In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of... In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large "nb_frames" field in the header but does not contain sufficient backing data, is provided, the loop over the frames would consume huge CPU and memory resources, since th
debian
CVE-2017-14057P4LOWCVSS 6.5fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14057 [MEDIUM] CVE-2017-14057: ffmpeg - In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) ... In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient backing data, is provided, the loops over the name and markers would consume huge CPU and memory resources, since th
debian
CVE-2017-14171P4LOWCVSS 6.5fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14171 [MEDIUM] CVE-2017-14171: ffmpeg - In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header(... In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted NSV file, which claims a large "table_entries_used" field in the header but does not contain sufficient backing data, is provided, the loop over 'table_entries_used' would consume huge CPU resou
debian
CVE-2017-14054P4LOWCVSS 6.5fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14054 [MEDIUM] CVE-2017-14054: ffmpeg - In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack o... In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted IVR file, which claims a large "len" field in the header but does not contain sufficient backing data, is provided, the first type==4 loop would consume huge CPU resources, since there is no EOF check inside t
debian
CVE-2020-22021P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.3.2-0+deb11u2 (bookworm)2020
CVE-2020-22021 [MEDIUM] CVE-2020-22021: ffmpeg - Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfil... Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service. Scope: local bookworm: resolved (fixed in 7:4.3.2-0+deb11u2) bullseye: resolved (fixed in 7:4.3.2-0+deb11u2) forky: resolved (fixed in 7:4.3.2-0+deb11u2) sid: resolved (fixed in 7:4.3.2-0+deb11u2) trixie:
debian
CVE-2020-22033P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.3.2-0+deb11u2 (bookworm)2020
CVE-2020-22033 [MEDIUM] CVE-2020-22033: ffmpeg - A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_v... A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a remote malicious user cause a Denial of Service. Scope: local bookworm: resolved (fixed in 7:4.3.2-0+deb11u2) bullseye: resolved (fixed in 7:4.3.2-0+deb11u2) forky: resolved (fixed in 7:4.3.2-0+deb11u2) sid: resolved (fixed in 7:4.3.2
debian
CVE-2020-20448P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-20448 [MEDIUM] CVE-2020-20448: ffmpeg - FFmpeg 4.1.3 is affected by a Divide By Zero issue via libavcodec/ratecontrol.c,... FFmpeg 4.1.3 is affected by a Divide By Zero issue via libavcodec/ratecontrol.c, which allows a remote malicious user to cause a Denial of Service. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2023-6604P4MEDIUMCVSS 5.3fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2023
CVE-2023-6604 [MEDIUM] CVE-2023-6604: ffmpeg - A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU ... A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation. Scope: local bookworm: resolved (fixed in 7:5.1.7-0+deb12u1) bullseye: resolved (fixed in 7:4.3.9-0+de
debian
CVE-2023-6602P4MEDIUMCVSS 5.3fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2023
CVE-2023-6602 [MEDIUM] CVE-2023-6602: ffmpeg - A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible dat... A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists. Scope: local bookworm: resolved (fixed in 7:5.1.7-0+deb12u1) bullseye: resolved (fixed in 7:4.3.9-0+deb11u1) forky: resolved (fixed in 7:7.1.1-1) sid: resolved (fixed in 7:7.1.1-1) trixie: resolved (fix
debian
CVE-2013-7010P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-7010 [MEDIUM] CVE-2013-7010: ffmpeg - Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 ... Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fix
debian
CVE-2018-7751P4MEDIUMCVSS 6.5fixed in ffmpeg 7:3.4.3-1 (bookworm)2018
CVE-2018-7751 [MEDIUM] CVE-2018-7751: ffmpeg - The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows r... The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file. Scope: local bookworm: resolved (fixed in 7:3.4.3-1) bullseye: resolved (fixed in 7:3.4.3-1) forky: resolved (fixed in 7:3.4.3-1) sid: resolved (fixed in 7:3.4.3-1) trixie: resolved (fixed in 7:3.4.3-1)
debian
CVE-2025-0518P4MEDIUMCVSS 4.8fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2025
CVE-2025-0518 [MEDIUM] CVE-2025-0518: ffmpeg - Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read S... Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C . This issue affects FFmpeg: 7.1. Issue was fixed: https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38
debian
CVE-2018-7557P4MEDIUMCVSS 6.5fixed in ffmpeg 7:3.4.3-1 (bookworm)2018
CVE-2018-7557 [MEDIUM] CVE-2018-7557: ffmpeg - The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 ... The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array read) via an AVI file with crafted dimensions within chroma subsampling data. Scope: local bookworm: resolved (fixed in 7:3.4.3-1) bullseye: resolved (fixed in 7:3.4.3-1) forky: resolved (fixed in 7:3.4.3-1) sid: resolved
debian
CVE-2017-17081P4MEDIUMCVSS 6.5fixed in ffmpeg 7:3.4.1-1 (bookworm)2017
CVE-2017-17081 [MEDIUM] CVE-2017-17081: ffmpeg - The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does... The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does not properly validate widths and heights, which allows remote attackers to cause a denial of service (integer signedness error and out-of-array read) via a crafted MPEG file. Scope: local bookworm: resolved (fixed in 7:3.4.1-1) bullseye: resolved (fixed in 7:3.4.1-1) forky: resolved (f
debian
CVE-2020-22028P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22028 [MEDIUM] CVE-2020-22028: ffmpeg - Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_vertically_8 at lib... Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_vertically_8 at libavfilter/vf_avgblur.c, which could cause a remote Denial of Service. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-2)
debian
Debian Ffmpeg vulnerabilities | cvebase