Debian Ffmpeg vulnerabilities
375 known vulnerabilities affecting debian/ffmpeg.
Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80
Vulnerabilities
Page 17 of 19
CVE-2020-22038P4LOWCVSS 6.5fixed in ffmpeg 7:4.4-5 (bookworm)2020
CVE-2020-22038 [MEDIUM] CVE-2020-22038: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c.
Scope: local
bookworm: resolved (fixed in 7:4.4-5)
bullseye: open
forky: resolved (fixed in 7:4.4-5)
sid: resolved (fixed in 7:4.4-5)
trixie: resolved (fixed in 7:4.4-5)
debian
CVE-2020-22042P4LOWCVSS 6.5fixed in ffmpeg 7:4.4-5 (bookworm)2020
CVE-2020-22042 [MEDIUM] CVE-2020-22042: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is a...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory leak in the link_filter_inouts function in libavfilter/graphparser.c.
Scope: local
bookworm: resolved (fixed in 7:4.4-5)
bullseye: resolved (fixed in 7:4.3.3-0+deb11u1)
forky: resolved (fixed in 7:4.4-5)
sid: resolved (fixed in 7:4.4-5)
trixie: resolved (fixed in 7:4.
debian
CVE-2020-22048P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22048 [MEDIUM] CVE-2020-22048: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22041P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22041 [MEDIUM] CVE-2020-22041: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22056P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22056 [MEDIUM] CVE-2020-22056: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossover.c.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2015-1207P4MEDIUMCVSS 6.5fixed in ffmpeg 7:2.6.1-1 (bookworm)2015
CVE-2015-1207 [MEDIUM] CVE-2015-1207: ffmpeg - Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2...
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
Scope: local
bookworm: resolved (fixed in 7:2.6.1-1)
bullseye: resolved (fixed in 7:2.6.1-1)
forky: resolved (fixed in 7:2.6.1-1)
sid: resolved (fixed in 7:2.6.1-1)
trixie: re
debian
CVE-2024-36616P4MEDIUMCVSS 6.5fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2024
CVE-2024-36616 [MEDIUM] CVE-2024-36616: ffmpeg - An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1....
An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.
Scope: local
bookworm: resolved (fixed in 7:5.1.5-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.7-0+deb11u1)
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolve
debian
CVE-2025-22919P4MEDIUMCVSS 6.5fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2025
CVE-2025-22919 [MEDIUM] CVE-2025-22919: ffmpeg - A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows at...
A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.
Scope: local
bookworm: resolved (fixed in 7:5.1.7-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.8-0+deb11u3)
forky: resolved (fixed in 7:7.1.1-1)
sid: resolved (fixed in 7:7.1.1-1)
trixie: resolved (fixed in 7:7.
debian
CVE-2024-36618P4MEDIUMCVSS 6.2fixed in ffmpeg 7:5.1.8-0+deb12u1 (bookworm)2024
CVE-2024-36618 [MEDIUM] CVE-2024-36618: ffmpeg - FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library ...
FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.
Scope: local
bookworm: resolved (fixed in 7:5.1.8-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.8-0+deb11u2)
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie
debian
CVE-2025-12343P4LOWCVSS 3.3fixed in ffmpeg 7:7.1.2-1 (forky)2025
CVE-2025-12343 [LOW] CVE-2025-12343: ffmpeg - A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backe...
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash
debian
CVE-2025-25473P4LOWCVSS 5.3fixed in ffmpeg 7:8.0.1-2 (forky)2025
CVE-2025-25473 [MEDIUM] CVE-2025-25473: ffmpeg - FFmpeg git master before commit c08d30 was discovered to contain a memory leak i...
FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 7:8.0.1-2)
sid: resolved (fixed in 7:8.0.1-2)
trixie: resolved (fixed in 7:7.1.3-0+deb13u1)
debian
CVE-2013-0860P4MEDIUMCVSS 4.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0860 [MEDIUM] CVE-2013-0860: ffmpeg - The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1...
The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL pointer dereference via crafted picture data.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolve
debian
CVE-2023-6601P4MEDIUMCVSS 4.7fixed in ffmpeg 7:6.1-1 (forky)2023
CVE-2023-6601 [MEDIUM] CVE-2023-6601: ffmpeg - A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing un...
A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 7:6.1-1)
sid: resolved (fixed in 7:6.1-1)
trixie: resolved (fixed in 7:6.1-1)
debian
CVE-2017-1000460P4MEDIUMCVSS 6.5fixed in ffmpeg 7:3.1.1-1 (bookworm)2017
CVE-2017-1000460 [MEDIUM] CVE-2017-1000460: ffmpeg - In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 p...
In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.
Scope: local
bookworm: resolved (fixed in 7:3.1.1-1)
bullseye: resolved (fixed in 7:3.1.1-1)
forky: resolved (
debian
CVE-2024-36617P4MEDIUMCVSS 6.2fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2024
CVE-2024-36617 [MEDIUM] CVE-2024-36617: ffmpeg - FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
Scope: local
bookworm: resolved (fixed in 7:5.1.5-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.7-0+deb11u1)
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2016-7562P4MEDIUMCVSS 5.5fixed in ffmpeg 7:3.1.4-1 (bookworm)2016
CVE-2016-7562 [MEDIUM] CVE-2016-7562: ffmpeg - The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 all...
The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.
Scope: local
bookworm: resolved (fixed in 7:3.1.4-1)
bullseye: resolved (fixed in 7:3.1.4-1)
forky: resolved (fixed in 7:3.1.4-1)
sid: resolved (fixed in 7:3.1.4-1)
trixie: resolved (fixed in 7:3.1
debian
CVE-2015-1208P4MEDIUMCVSS 5.5fixed in ffmpeg 7:2.5.3-1 (bookworm)2015
CVE-2015-1208 [MEDIUM] CVE-2015-1208: ffmpeg - Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpe...
Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.
Scope: local
bookworm: resolved (fixed in 7:2.5.3-1)
bullseye: resolved (fixed in 7:2.5.3-1)
forky: resolved (fixed in 7:2.5.3-1)
sid: resolved (fixed in 7:2.5.3-1)
debian
CVE-2014-9319P4MEDIUMCVSS 5.0fixed in ffmpeg 2.4.4-1 (bookworm)2014
CVE-2014-9319 [MEDIUM] CVE-2014-9319: ffmpeg - The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1...
The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted .bit file.
Scope: local
bookworm: resolved (fixed in 2.4.4-1)
bullseye: resolved (fixed in 2.4.4-1)
forky: resolved (fixed in 2.4.4-1)
sid: resolved (f
debian
CVE-2021-3566P4MEDIUMCVSS 5.5fixed in ffmpeg 7:4.3-2 (bookworm)2021
CVE-2021-3566 [MEDIUM] CVE-2021-3566: ffmpeg - Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' functio...
Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the `-vcodec copy` option is passed to ffmpeg).
Scope: local
bookw
debian
CVE-2022-3341P4MEDIUMCVSS 5.3fixed in ffmpeg 7:5.1-1 (bookworm)2022
CVE-2022-3341 [MEDIUM] CVE-2022-3341: ffmpeg - A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_heade...
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash.
Scope: local
bookworm: resolved (fixed in 7:5.1-1)
bullseye: resolved
debian