cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 18 of 19
CVE-2022-1475P4MEDIUMCVSS 5.5fixed in ffmpeg 7:4.4.2-1 (bookworm)2022
CVE-2022-1475 [MEDIUM] CVE-2022-1475: ffmpeg - An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and ... An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file. Scope: local bookworm: resolved (fixed in 7:4.4.2-1) bullseye: resolved (fixed in 7:4.3.4-0+deb11u1) forky: resolved (fixed in 7:4.4.2-1) sid: resolved (fixed in 7:4.4.2-1) trixie: resolved
debian
CVE-2024-35369P4MEDIUMCVSS 5.5fixed in ffmpeg 7:7.0.1-3 (forky)2024
CVE-2024-35369 [MEDIUM] CVE-2024-35369: ffmpeg - In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a p... In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process. Scope: local
debian
CVE-2011-4353P4MEDIUMCVSS 4.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-4353 [MEDIUM] CVE-2011-4353: ffmpeg - The (1) av_image_fill_pointers, (2) vp5_parse_coeff, and (3) vp6_parse_coeff fun... The (1) av_image_fill_pointers, (2) vp5_parse_coeff, and (3) vp6_parse_coeff functions in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted VP5 or VP6 stream. Scope:
debian
CVE-2025-1816P4LOWCVSS 5.3fixed in ffmpeg 7:7.1.1-1 (forky)2025
CVE-2025-1816 [MEDIUM] CVE-2025-1816: ffmpeg - A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57... A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This affects the function audio_element_obu of the file libavformat/iamf_parse.c of the component IAMF File Handler. The manipulation of the argument num_parameters leads to memory leak. It is possible to initiate the attack remotely. The exploit has bee
debian
CVE-2016-7555P4MEDIUMCVSS 5.5fixed in ffmpeg 7:3.1.4-1 (bookworm)2016
CVE-2016-7555 [MEDIUM] CVE-2016-7555: ffmpeg - The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is v... The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure. Scope: local bookworm: resolved (fixed in 7:3.1.4-1) bullseye: resolved (fixed in 7:3.1.4-1) forky: resolved (fixed in 7:3.1.4-1) sid: resolved (fixed in 7:3.1.4-1) trixie: resolved (fixed in 7:3.1.4-1
debian
CVE-2025-10256P4MEDIUMCVSS 5.3fixed in ffmpeg 7:4.3.9-0+deb11u2 (bullseye)2025
CVE-2025-10256 [MEDIUM] CVE-2025-10256: ffmpeg - A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter ... A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to deref
debian
CVE-2011-3973P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3973 [MEDIUM] CVE-2011-3973: ffmpeg - cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows rem... cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-336
debian
CVE-2018-14395P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-14395 [MEDIUM] CVE-2018-14395: ffmpeg - libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial ... libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted audio file when converting to the MOV audio format. Scope: local bookworm: resolved (fixed in 7:4.0.2-1) bullseye: resolved (fixed in 7:4.0.2-1) forky: resolved (fixed in 7:4.0.2-1) sid: resolved (fixed
debian
CVE-2021-38114P4CRITICALCVSS 9.3fixed in ffmpeg 7:4.4.1-1 (bookworm)2021
CVE-2021-38114 [CRITICAL] CVE-2021-38114: ffmpeg - libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_... libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a similar issue to CVE-2013-0868. Scope: local bookworm: resolved (fixed in 7:4.4.1-1) bullseye: resolved (fixed in 7:4.3.3-0+deb11u1) forky: resolved (fixed in 7:4.4.1-1) sid: resolved (fixed in 7:4.4.1-1) trixie: resolved (fixed in 7:4.4.1-1)
debian
CVE-2016-7905P4MEDIUMCVSS 5.5fixed in ffmpeg 7:3.1.4-1 (bookworm)2016
CVE-2016-7905 [MEDIUM] CVE-2016-7905: ffmpeg - The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows... The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file. Scope: local bookworm: resolved (fixed in 7:3.1.4-1) bullseye: resolved (fixed in 7:3.1.4-1) forky: resolved (fixed in 7:3.1.4-1) sid: resolved (fixed in 7:3.1.4-1) trixie: resolved (fixed in 7:3.1.
debian
CVE-2020-13904P4MEDIUMCVSS 5.5fixed in ffmpeg 7:4.3.1-1 (bookworm)2020
CVE-2020-13904 [MEDIUM] CVE-2020-13904: ffmpeg - FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3... FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c. Scope: local bookworm: resolved (fixed in 7:4.3.1-1) bullseye: resolved (fixed in 7:4.3.1-1) forky: resolved (fixed in 7:4.3.1-1) si
debian
CVE-2016-9561P4LOWCVSS 5.5fixed in ffmpeg 7:3.2.4-1 (bookworm)2016
CVE-2016-9561 [MEDIUM] CVE-2016-9561: ffmpeg - The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.... The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file. Scope: local bookworm: resolved (fixed in 7:3.2.4-1) bullseye: resolved (fixed in 7:3.2.4-1) forky: resolved (fixed in 7:3.2.4-1) sid: resolved (fixed in
debian
CVE-2017-5024P4MEDIUMCVSS 5.5fixed in ffmpeg 7:3.2.4-1 (bookworm)2017
CVE-2017-5024 [MEDIUM] CVE-2017-5024: ffmpeg - FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed... FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file. Scope: local bookworm: resolved (fixed in 7:3.2.4-1) bullseye: resolved (fixed in 7:3.2.4-1) forky: resolved (fixed in 7:3.2.4-1) sid: resolved (fixed in 7:
debian
CVE-2017-5025P4MEDIUMCVSS 5.5fixed in ffmpeg 7:3.2.4-1 (bookworm)2017
CVE-2017-5025 [MEDIUM] CVE-2017-5025: ffmpeg - FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed... FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file. Scope: local bookworm: resolved (fixed in 7:3.2.4-1) bullseye: resolved (fixed in 7:3.2.4-1) forky: resolved (fixed in 7:3.2.4-1) sid: resolved (fixed in 7:
debian
CVE-2011-3893P4MEDIUMCVSS 5.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3893 [MEDIUM] CVE-2011-3893: ffmpeg - Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis... Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) tr
debian
CVE-2011-3974P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3974 [MEDIUM] CVE-2011-3974: ffmpeg - Integer signedness error in the decode_residual_inter function in cavsdec.c in l... Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, a different vulnerability than CVE-2011-3362. Scope: local bookwo
debian
CVE-2016-7785P4MEDIUMCVSS 5.5fixed in ffmpeg 7:3.1.4-1 (bookworm)2016
CVE-2016-7785 [MEDIUM] CVE-2016-7785: ffmpeg - The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows... The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file. Scope: local bookworm: resolved (fixed in 7:3.1.4-1) bullseye: resolved (fixed in 7:3.1.4-1) forky: resolved (fixed in 7:3.1.4-1) sid: resolved (fixed in 7:3.1.4-1) trixie: resolved (fixed in 7:3.1.4-1)
debian
CVE-2016-7122P4MEDIUMCVSS 5.5fixed in ffmpeg 7:3.1.4-1 (bookworm)2016
CVE-2016-7122 [MEDIUM] CVE-2016-7122: ffmpeg - The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vu... The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure. Scope: local bookworm: resolved (fixed in 7:3.1.4-1) bullseye: resolved (fixed in 7:3.1.4-1) forky: resolved (fixed in 7:3.1.4-1) sid: resolved (fixed in 7:3.1.4-1) trixie: resolved (fixed in 7:3.1.
debian
CVE-2018-14394P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.0.2-1 (bookworm)2018
CVE-2018-14394 [MEDIUM] CVE-2018-14394: ffmpeg - libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial o... libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted Waveform audio file. Scope: local bookworm: resolved (fixed in 7:4.0.2-1) bullseye: resolved (fixed in 7:4.0.2-1) forky: resolved (fixed in 7:4.0.2-1) sid: resolved (fixed in 7:4.0.2-1) trixie: resolved (
debian
CVE-2023-50007P4MEDIUMCVSS 4.0fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2023
CVE-2023-50007 [MEDIUM] CVE-2023-50007: ffmpeg - FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of ... FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component. Scope: local bookworm: resolved (fixed in 7:5.1.7-0+deb12u1) bullseye: resolved forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolved (fixed in 7:7.0.1-3)
debian
Debian Ffmpeg vulnerabilities | cvebase