cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 17 of 19
CVE-2020-22038P4LOWCVSS 6.5fixed in ffmpeg 7:4.4-5 (bookworm)2020
CVE-2020-22038 [MEDIUM] CVE-2020-22038: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t... A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c. Scope: local bookworm: resolved (fixed in 7:4.4-5) bullseye: open forky: resolved (fixed in 7:4.4-5) sid: resolved (fixed in 7:4.4-5) trixie: resolved (fixed in 7:4.4-5)
debian
CVE-2020-22042P4LOWCVSS 6.5fixed in ffmpeg 7:4.4-5 (bookworm)2020
CVE-2020-22042 [MEDIUM] CVE-2020-22042: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is a... A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory leak in the link_filter_inouts function in libavfilter/graphparser.c. Scope: local bookworm: resolved (fixed in 7:4.4-5) bullseye: resolved (fixed in 7:4.3.3-0+deb11u1) forky: resolved (fixed in 7:4.4-5) sid: resolved (fixed in 7:4.4-5) trixie: resolved (fixed in 7:4.
debian
CVE-2020-22048P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22048 [MEDIUM] CVE-2020-22048: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t... A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22041P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22041 [MEDIUM] CVE-2020-22041: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t... A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22056P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22056 [MEDIUM] CVE-2020-22056: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t... A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossover.c. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2015-1207P4MEDIUMCVSS 6.5fixed in ffmpeg 7:2.6.1-1 (bookworm)2015
CVE-2015-1207 [MEDIUM] CVE-2015-1207: ffmpeg - Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2... Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file. Scope: local bookworm: resolved (fixed in 7:2.6.1-1) bullseye: resolved (fixed in 7:2.6.1-1) forky: resolved (fixed in 7:2.6.1-1) sid: resolved (fixed in 7:2.6.1-1) trixie: re
debian
CVE-2024-36616P4MEDIUMCVSS 6.5fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2024
CVE-2024-36616 [MEDIUM] CVE-2024-36616: ffmpeg - An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.... An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file. Scope: local bookworm: resolved (fixed in 7:5.1.5-0+deb12u1) bullseye: resolved (fixed in 7:4.3.7-0+deb11u1) forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolve
debian
CVE-2025-22919P4MEDIUMCVSS 6.5fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2025
CVE-2025-22919 [MEDIUM] CVE-2025-22919: ffmpeg - A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows at... A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file. Scope: local bookworm: resolved (fixed in 7:5.1.7-0+deb12u1) bullseye: resolved (fixed in 7:4.3.8-0+deb11u3) forky: resolved (fixed in 7:7.1.1-1) sid: resolved (fixed in 7:7.1.1-1) trixie: resolved (fixed in 7:7.
debian
CVE-2024-36618P4MEDIUMCVSS 6.2fixed in ffmpeg 7:5.1.8-0+deb12u1 (bookworm)2024
CVE-2024-36618 [MEDIUM] CVE-2024-36618: ffmpeg - FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library ... FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition. Scope: local bookworm: resolved (fixed in 7:5.1.8-0+deb12u1) bullseye: resolved (fixed in 7:4.3.8-0+deb11u2) forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie
debian
CVE-2025-12343P4LOWCVSS 3.3fixed in ffmpeg 7:7.1.2-1 (forky)2025
CVE-2025-12343 [LOW] CVE-2025-12343: ffmpeg - A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backe... A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash
debian
CVE-2025-25473P4LOWCVSS 5.3fixed in ffmpeg 7:8.0.1-2 (forky)2025
CVE-2025-25473 [MEDIUM] CVE-2025-25473: ffmpeg - FFmpeg git master before commit c08d30 was discovered to contain a memory leak i... FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 7:8.0.1-2) sid: resolved (fixed in 7:8.0.1-2) trixie: resolved (fixed in 7:7.1.3-0+deb13u1)
debian
CVE-2013-0860P4MEDIUMCVSS 4.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0860 [MEDIUM] CVE-2013-0860: ffmpeg - The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1... The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL pointer dereference via crafted picture data. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolve
debian
CVE-2023-6601P4MEDIUMCVSS 4.7fixed in ffmpeg 7:6.1-1 (forky)2023
CVE-2023-6601 [MEDIUM] CVE-2023-6601: ffmpeg - A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing un... A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 7:6.1-1) sid: resolved (fixed in 7:6.1-1) trixie: resolved (fixed in 7:6.1-1)
debian
CVE-2017-1000460P4MEDIUMCVSS 6.5fixed in ffmpeg 7:3.1.1-1 (bookworm)2017
CVE-2017-1000460 [MEDIUM] CVE-2017-1000460: ffmpeg - In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 p... In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception. Scope: local bookworm: resolved (fixed in 7:3.1.1-1) bullseye: resolved (fixed in 7:3.1.1-1) forky: resolved (
debian
CVE-2024-36617P4MEDIUMCVSS 6.2fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2024
CVE-2024-36617 [MEDIUM] CVE-2024-36617: ffmpeg - FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder. FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder. Scope: local bookworm: resolved (fixed in 7:5.1.5-0+deb12u1) bullseye: resolved (fixed in 7:4.3.7-0+deb11u1) forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2016-7562P4MEDIUMCVSS 5.5fixed in ffmpeg 7:3.1.4-1 (bookworm)2016
CVE-2016-7562 [MEDIUM] CVE-2016-7562: ffmpeg - The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 all... The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file. Scope: local bookworm: resolved (fixed in 7:3.1.4-1) bullseye: resolved (fixed in 7:3.1.4-1) forky: resolved (fixed in 7:3.1.4-1) sid: resolved (fixed in 7:3.1.4-1) trixie: resolved (fixed in 7:3.1
debian
CVE-2015-1208P4MEDIUMCVSS 5.5fixed in ffmpeg 7:2.5.3-1 (bookworm)2015
CVE-2015-1208 [MEDIUM] CVE-2015-1208: ffmpeg - Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpe... Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file. Scope: local bookworm: resolved (fixed in 7:2.5.3-1) bullseye: resolved (fixed in 7:2.5.3-1) forky: resolved (fixed in 7:2.5.3-1) sid: resolved (fixed in 7:2.5.3-1)
debian
CVE-2014-9319P4MEDIUMCVSS 5.0fixed in ffmpeg 2.4.4-1 (bookworm)2014
CVE-2014-9319 [MEDIUM] CVE-2014-9319: ffmpeg - The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1... The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted .bit file. Scope: local bookworm: resolved (fixed in 2.4.4-1) bullseye: resolved (fixed in 2.4.4-1) forky: resolved (fixed in 2.4.4-1) sid: resolved (f
debian
CVE-2021-3566P4MEDIUMCVSS 5.5fixed in ffmpeg 7:4.3-2 (bookworm)2021
CVE-2021-3566 [MEDIUM] CVE-2021-3566: ffmpeg - Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' functio... Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the `-vcodec copy` option is passed to ffmpeg). Scope: local bookw
debian
CVE-2022-3341P4MEDIUMCVSS 5.3fixed in ffmpeg 7:5.1-1 (bookworm)2022
CVE-2022-3341 [MEDIUM] CVE-2022-3341: ffmpeg - A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_heade... A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash. Scope: local bookworm: resolved (fixed in 7:5.1-1) bullseye: resolved
debian
Debian Ffmpeg vulnerabilities | cvebase