Debian Ffmpeg vulnerabilities
375 known vulnerabilities affecting debian/ffmpeg.
Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80
Vulnerabilities
Page 15 of 19
CVE-2017-15186P4MEDIUMCVSS 6.5fixed in ffmpeg 7:3.4-1 (bookworm)2017
CVE-2017-15186 [MEDIUM] CVE-2017-15186: ffmpeg - Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to...
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
Scope: local
bookworm: resolved (fixed in 7:3.4-1)
bullseye: resolved (fixed in 7:3.4-1)
forky: resolved (fixed in 7:3.4-1)
sid: resolved (fixed in 7:3.4-1)
trixie: resolved (fixed in 7:3.4-1)
debian
CVE-2019-9718P4LOWCVSS 6.5fixed in ffmpeg 7:4.1.3-1 (bookworm)2019
CVE-2019-9718 [MEDIUM] CVE-2019-9718: ffmpeg - In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attack...
In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
Scope: local
bookworm: resolved (fixed in 7:4.1.3-1)
bullseye: resolved (fixed in 7:4.1.3-1)
forky: resolved (fixed in 7:4.1.
debian
CVE-2018-12458P4LOWCVSS 6.5fixed in ffmpeg 7:3.4.3-1 (bookworm)2018
CVE-2018-12458 [MEDIUM] CVE-2018-12458: ffmpeg - An improper integer type in the mpeg4_encode_gop_header function in libavcodec/m...
An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.
Scope: local
bookworm: resolved (fixed in 7:3.4.3-1)
bullseye: resolved (fixed in 7:3.4.3-1)
forky: resolved (fixed in 7:3.4.3-1)
sid: re
debian
CVE-2020-22020P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22020 [MEDIUM] CVE-2020-22020: ffmpeg - Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in li...
Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause a Denial of Service.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2019-9721P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.1.3-1 (bookworm)2019
CVE-2019-9721 [MEDIUM] CVE-2019-9721: ffmpeg - A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attacke...
A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
Scope: local
bookworm: resolved (fixed in 7:4.1.3-1)
bullseye: resolved (fixed in 7:4.1.3-1)
forky: resolved (fixed in 7:4.1.3-1)
debian
CVE-2025-59731P4MEDIUMCVSS 6.9fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2025
CVE-2025-59731 [MEDIUM] CVE-2025-59731: ffmpeg - When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified ...
When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to calculate the output data. We read rle_raw_size from the input file at [0], we decompress and decode into the buffer td->rle_raw_data of size rle_raw_size at [1], and then at [2] we will access entries in this buffer
debian
CVE-2024-36619P4LOWCVSS 5.3fixed in ffmpeg 7:7.1-3 (forky)2024
CVE-2024-36619 [MEDIUM] CVE-2024-36619: ffmpeg - FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec librar...
FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 7:7.1-3)
sid: resolved (fixed in 7:7.1-3)
trixie: resolved (fixed in 7:7.1-3)
debian
CVE-2025-7700P4MEDIUMCVSS 5.3fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2025
CVE-2025-7700 [MEDIUM] CVE-2025-7700: ffmpeg - A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check...
A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
Scope: local
bookworm: resolved (fixed in 7:5.1
debian
CVE-2018-10001P4LOWCVSS 6.5fixed in ffmpeg 7:3.4.3-1 (bookworm)2018
CVE-2018-10001 [MEDIUM] CVE-2018-10001: ffmpeg - The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allo...
The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file.
Scope: local
bookworm: resolved (fixed in 7:3.4.3-1)
bullseye: resolved (fixed in 7:3.4.3-1)
forky: resolved (fixed in 7:3.4.3-1)
sid: resolved (fixed in 7:3.4.3-1)
trixie: resolved (fixed in 7:3.4.3-1
debian
CVE-2019-13390P4LOWCVSS 6.5fixed in ffmpeg 7:4.2.1-1 (bookworm)2019
CVE-2019-13390 [MEDIUM] CVE-2019-13390: ffmpeg - In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat...
In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat/rawenc.c.
Scope: local
bookworm: resolved (fixed in 7:4.2.1-1)
bullseye: resolved (fixed in 7:4.2.1-1)
forky: resolved (fixed in 7:4.2.1-1)
sid: resolved (fixed in 7:4.2.1-1)
trixie: resolved (fixed in 7:4.2.1-1)
debian
CVE-2018-6392P4MEDIUMCVSS 6.5fixed in ffmpeg 7:3.4.2-1 (bookworm)2018
CVE-2018-6392 [MEDIUM] CVE-2018-6392: ffmpeg - The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 ...
The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows remote attackers to cause a denial of service (out-of-array access) via a crafted MP4 file.
Scope: local
bookworm: resolved (fixed in 7:3.4.2-1)
bullseye: resolved (fixed in 7:3.4.2-1)
forky: resolved (fixed in 7:3.4.2-1)
sid: resolved (fixed in 7:3.4.2-1)
trixie: resolved (fixed i
debian
CVE-2020-22037P4LOWCVSS 6.5fixed in ffmpeg 7:4.4.1-1 (bookworm)2020
CVE-2020-22037 [MEDIUM] CVE-2020-22037: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in a...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.
Scope: local
bookworm: resolved (fixed in 7:4.4.1-1)
bullseye: resolved (fixed in 7:4.3.3-0+deb11u1)
forky: resolved (fixed in 7:4.4.1-1)
sid: resolved (fixed in 7:4.4.1-1)
trixie: resolved (fixed in 7:4.4.1-1)
debian
CVE-2018-13303P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-13303 [MEDIUM] CVE-2018-13303: ffmpeg - In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in th...
In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in libavcodec/ac3_parser.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4, leading to a denial of service.
Scope: local
bookworm: resolved (fixed in 7:4.0.2-1)
bullseye: resolved (fixed in 7:4.0.2-1)
forky: resolved
debian
CVE-2018-13301P4LOWCVSS 6.5fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-13301 [MEDIUM] CVE-2018-13301: ffmpeg - In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, th...
In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4, leading to a denial of service.
Scope: local
bookworm: resolved (fixed in 7:4.0.2-1)
bullseye: resolved (fixed in 7:4.0.2-1)
forky
debian
CVE-2020-22026P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22026 [MEDIUM] CVE-2020-22026: ffmpeg - Buffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function ...
Buffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function at libavfilter/af_tremolo.c, which could let a remote malicious user cause a Denial of Service.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2
debian
CVE-2018-13304P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-13304 [MEDIUM] CVE-2018-13304: ffmpeg - In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between t...
In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger an assertion failure while converting a crafted AVI file to MPEG4, leading to a denial of service, related to error_resilience.c, h263dec.c, and mpeg4videodec.c.
Scope: local
bookworm: resolved (fixed in 7:4.0.2-1)
bu
debian
CVE-2019-1000016P4LOWCVSS 6.5fixed in ffmpeg 7:4.1.1-1 (bookworm)2019
CVE-2019-1000016 [MEDIUM] CVE-2019-1000016: ffmpeg - FFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulner...
FFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability in libavcodec/cbs_av1.c that can result in Denial of service. This attack appears to be exploitable via specially crafted AV1 file has to be provided as input. This vulnerability appears to have been fixed in after commit b97a4b658814b2de8b9f2a3bce491c002d34de31.
Scope: loca
debian
CVE-2020-22024P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22024 [MEDIUM] CVE-2020-22024: ffmpeg - Buffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in li...
Buffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in libavfilter/vf_lagfun.c, which could let a remote malicious user cause Denial of Service.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-21697P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.4-5 (bookworm)2020
CVE-2020-21697 [MEDIUM] CVE-2020-21697: ffmpeg - A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpege...
A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a denial of service (DOS) via a crafted avi file.
Scope: local
bookworm: resolved (fixed in 7:4.4-5)
bullseye: resolved (fixed in 7:4.3.3-0+deb11u1)
forky: resolved (fixed in 7:4.4-5)
sid: resolved (fixed in 7:4.4-5)
trixie: resolved (fixed in 7:4.4-5)
debian
CVE-2009-4632P4MEDIUMCVSS 5.8fixed in ffmpeg 4:0.5+svn20090706-3 (bookworm)2009
CVE-2009-4632 [MEDIUM] CVE-2009-4632: ffmpeg - oggparsevorbis.c in FFmpeg 0.5 does not properly perform certain pointer arithme...
oggparsevorbis.c in FFmpeg 0.5 does not properly perform certain pointer arithmetic, which might allow remote attackers to obtain sensitive memory contents and cause a denial of service via a crafted file that triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 4:0.5+svn20090706-3)
bullseye: resolved (fixed in 4:0.5+svn20090706-3)
forky: resolve
debian