cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 19 of 19
CVE-2016-8595P4MEDIUMCVSS 5.5fixed in ffmpeg 7:3.1.5-1 (bookworm)2016
CVE-2016-8595 [MEDIUM] CVE-2016-8595: ffmpeg - The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows ... The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file. Scope: local bookworm: resolved (fixed in 7:3.1.5-1) bullseye: resolved (fixed in 7:3.1.5-1) forky: resolved (fixed in 7:3.1.5-1) sid: resolved (fixed in 7:3.1.5-1) trixie: resolved (fixed in 7:3.1.5-1)
debian
CVE-2016-6881P4LOWCVSS 5.5fixed in ffmpeg 7:3.1.3-1 (bookworm)2016
CVE-2016-6881 [MEDIUM] CVE-2016-6881: ffmpeg - The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows r... The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file. Scope: local bookworm: resolved (fixed in 7:3.1.3-1) bullseye: resolved (fixed in 7:3.1.3-1) forky: resolved (fixed in 7:3.1.3-1) sid: resolved (fixed in 7:3.1.3-1) trixie: resolved (fixed in 7:3.1.3-1)
debian
CVE-2013-3672P4MEDIUMCVSS 4.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-3672 [MEDIUM] CVE-2013-3672: ffmpeg - The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before 1.2.1 d... The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before 1.2.1 does not validate the relationship between a horizontal coordinate and a width value, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted American Laser Games (ALG) MM Video data. Scope: local bookworm: resolved (fixed i
debian
CVE-2020-23906P4MEDIUMCVSS 5.5fixed in ffmpeg 7:4.3.1-1 (bookworm)2020
CVE-2020-23906 [MEDIUM] CVE-2020-23906: ffmpeg - FFmpeg N-98388-g76a3ee996b allows attackers to cause a denial of service (DoS) v... FFmpeg N-98388-g76a3ee996b allows attackers to cause a denial of service (DoS) via a crafted audio file due to insufficient verification of data authenticity. Scope: local bookworm: resolved (fixed in 7:4.3.1-1) bullseye: resolved (fixed in 7:4.3.1-1) forky: resolved (fixed in 7:4.3.1-1) sid: resolved (fixed in 7:4.3.1-1) trixie: resolved (fixed in 7:4.3.1-1)
debian
CVE-2021-28429P4MEDIUMCVSS 5.5fixed in ffmpeg 7:4.4-5 (bookworm)2021
CVE-2021-28429 [MEDIUM] CVE-2021-28429: ffmpeg - Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.... Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial of service (DoS) via crafted .mov file. Scope: local bookworm: resolved (fixed in 7:4.4-5) bullseye: resolved (fixed in 7:4.3.3-0+deb11u1) forky: resolved (fixed in 7:4.4-5) sid: resolved (fixed in 7:4.4-5) trixie: reso
debian
CVE-2009-4636P4MEDIUMCVSS 4.3fixed in ffmpeg 4:0.5+svn20090706-3 (bookworm)2009
CVE-2009-4636 [MEDIUM] CVE-2009-4636: ffmpeg - FFmpeg 0.5 allows remote attackers to cause a denial of service (hang) via a cra... FFmpeg 0.5 allows remote attackers to cause a denial of service (hang) via a crafted file that triggers an infinite loop. Scope: local bookworm: resolved (fixed in 4:0.5+svn20090706-3) bullseye: resolved (fixed in 4:0.5+svn20090706-3) forky: resolved (fixed in 4:0.5+svn20090706-3) sid: resolved (fixed in 4:0.5+svn20090706-3) trixie: resolved (fixed in 4:0.5+svn200907
debian
CVE-2010-4704P4LOWCVSS 4.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2010
CVE-2010-4704 [MEDIUM] CVE-2010-4704: ffmpeg - libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows... libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function. NOTE: this might overlap CVE-2011-0480. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (f
debian
CVE-2009-4639P4LOWCVSS 4.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2009
CVE-2009-4639 [MEDIUM] CVE-2009-4639: ffmpeg - The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attac... The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers a divide-by-zero error. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved (fix
debian
CVE-2024-31585P4MEDIUMCVSS 5.3fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2024
CVE-2024-31585 [MEDIUM] CVE-2024-31585: ffmpeg - FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulner... FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. Scope: local bookworm: resolved (fixed in 7:5.1.5-0+deb12u1) bullseye: resolved forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3)
debian
CVE-2011-3936P4MEDIUMCVSS 4.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3936 [MEDIUM] CVE-2011-3936: ffmpeg - The dv_extract_audio function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.... The dv_extract_audio function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DV file. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bul
debian
CVE-2013-3670P4MEDIUMCVSS 4.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-3670 [MEDIUM] CVE-2013-3670: ffmpeg - The rle_unpack function in vmdav.c in libavcodec in FFmpeg git 20130328 through ... The rle_unpack function in vmdav.c in libavcodec in FFmpeg git 20130328 through 20130501 does not properly use the bytestream2 API, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted RLE data. NOTE: the vendor has listed this as an issue fixed in 1.2.1, but the issue is actually in new code that w
debian
CVE-2023-51796P4LOWCVSS 3.6fixed in ffmpeg 7:7.0.1-3 (forky)2023
CVE-2023-51796 [LOW] CVE-2023-51796: ffmpeg - Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att... Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2011-2161P4MEDIUMCVSS 4.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-2161 [MEDIUM] CVE-2011-2161: ffmpeg - The ape_read_header function in ape.c in libavformat in FFmpeg before 0.5.4, as ... The ape_read_header function in ape.c in libavformat in FFmpeg before 0.5.4, as used in MPlayer, VideoLAN VLC media player, and other products, allows remote attackers to cause a denial of service (application crash) via an APE (aka Monkey's Audio) file that contains a header but no frames. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixe
debian
CVE-2012-6618P4LOWCVSS 2.6fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-6618 [LOW] CVE-2012-6618: ffmpeg - The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2... The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a crafted MP3 file, possibly related to frame size or lack of sufficient "frames to estimate rate." Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed i
debian
CVE-2008-3230P4LOWCVSS 1.9fixed in ffmpeg 0.svn20080206-16 (bookworm)2008
CVE-2008-3230 [LOW] CVE-2008-3230: ffmpeg - The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of serv... The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by lol-giftopnm.gif. Scope: local bookworm: resolved (fixed in 0.svn20080206-16) bullseye: resolved (fixed in 0.svn20080206-16) forky: resolved (fixed in 0.svn20080206-16) sid: resolved (fixed in 0
debian
Debian Ffmpeg vulnerabilities | cvebase