cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 2 of 19
CVE-2012-5360P3HIGHCVSS 8.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-5360 [HIGH] CVE-2012-5360: ffmpeg - Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary co... Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted QT file. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved (fixed in 7:2.4.1-1)
debian
CVE-2024-35366P3CRITICALCVSS 9.1fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2024
CVE-2024-35366 [CRITICAL] CVE-2024-35366: ffmpeg - FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options... FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking. Scope: local bookworm: resolved (fixed in 7:5.1.5-0+deb12u1)
debian
CVE-2011-3504P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3504 [CRITICAL] CVE-2011-3504: ffmpeg - The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate me... The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved (fixed in 7:2.4.1-1)
debian
CVE-2017-7863P3CRITICALCVSS 9.8fixed in ffmpeg 7:3.2.4-1 (bookworm)2017
CVE-2017-7863 [CRITICAL] CVE-2017-7863: ffmpeg - FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffe... FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c. Scope: local bookworm: resolved (fixed in 7:3.2.4-1) bullseye: resolved (fixed in 7:3.2.4-1) forky: resolved (fixed in 7:3.2.4-1) sid: resolved (fixed in 7:3.2.4-1) trixie: resolved (fixed in 7:3.2.4-1)
debian
CVE-2009-4633P3CRITICALCVSS 10.0fixed in ffmpeg 4:0.5+svn20090706-3 (bookworm)2009
CVE-2009-4633 [CRITICAL] CVE-2009-4633: ffmpeg - vorbis_dec.c in FFmpeg 0.5 uses an assignment operator when a comparison operato... vorbis_dec.c in FFmpeg 0.5 uses an assignment operator when a comparison operator was intended, which might allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted file that modifies a loop counter and triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 4:0.5+svn20090706-3) bullseye: resolve
debian
CVE-2019-17542P3CRITICALCVSS 9.8fixed in ffmpeg 7:4.2.1-1 (bookworm)2019
CVE-2019-17542 [CRITICAL] CVE-2019-17542: ffmpeg - FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because o... FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c. Scope: local bookworm: resolved (fixed in 7:4.2.1-1) bullseye: resolved (fixed in 7:4.2.1-1) forky: resolved (fixed in 7:4.2.1-1) sid: resolved (fixed in 7:4.2.1-1) trixie: resolved (fixed in 7:4.2.1-1)
debian
CVE-2009-0385P3CRITICALCVSS 9.3fixed in ffmpeg 0.svn20080206-16 (bookworm)2009
CVE-2009-0385 [CRITICAL] CVE-2009-0385: ffmpeg - Integer signedness error in the fourxm_read_header function in libavformat/4xm.c... Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.svn20080206-16) bullseye: resolved (fixed in 0.svn200
debian
CVE-2020-24020P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3.1-1 (bookworm)2020
CVE-2020-24020 [HIGH] CVE-2020-24020: ffmpeg - Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavf... Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavfilter/dnn/dnn_backend_native_layer_pad.c due to a call to memcpy without length checks, which could let a remote malicious user execute arbitrary code. Scope: local bookworm: resolved (fixed in 7:4.3.1-1) bullseye: resolved forky: resolved (fixed in 7:4.3.1-1) sid: resolved (fixed in 7:4.
debian
CVE-2022-4907P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4907 [HIGH] CVE-2022-4907: chromium - Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a re... Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1) sid: resolved
debian
CVE-2024-31581P3LOWCVSS 9.8fixed in ffmpeg 7:7.0.1-3 (forky)2024
CVE-2024-31581 [CRITICAL] CVE-2024-31581: ffmpeg - FFmpeg version n6.1 was discovered to contain an improper validation of array in... FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within the application. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolv
debian
CVE-2020-22032P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22032 [HIGH] CVE-2020-22032: ffmpeg - A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_e... A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4
debian
CVE-2020-22025P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22025 [HIGH] CVE-2020-22025: ffmpeg - A heap-based Buffer Overflow vulnerability exists in gaussian_blur at libavfilte... A heap-based Buffer Overflow vulnerability exists in gaussian_blur at libavfilter/vf_edgedetect.c, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2021-38171P3CRITICALCVSS 9.8fixed in ffmpeg 7:4.4.1-1 (bookworm)2021
CVE-2021-38171 [CRITICAL] CVE-2021-38171: ffmpeg - adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the ... adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted. Scope: local bookworm: resolved (fixed in 7:4.4.1-1) bullseye: resolved (fixed in 7:4.3.3-0+deb11u1) forky: resolved (fixed in 7:4.4.1-1) sid: resolved (fixed in 7:4.4.1-
debian
CVE-2024-35368P3CRITICALCVSS 9.8fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2024
CVE-2024-35368 [CRITICAL] CVE-2024-35368: ffmpeg - FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function w... FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c. Scope: local bookworm: resolved (fixed in 7:5.1.7-0+deb12u1) bullseye: resolved (fixed in 7:4.3.8-0+deb11u2) forky: resolved (fixed in 7:7.1-3) sid: resolved (fixed in 7:7.1-3) trixie: resolved (fixed in 7:7.1-3)
debian
CVE-2020-22036P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22036 [HIGH] CVE-2020-22036: ffmpeg - A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra ... A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-
debian
CVE-2020-21688P3HIGHCVSS 8.8fixed in ffmpeg 7:4.4-5 (bookworm)2020
CVE-2020-21688 [HIGH] CVE-2020-21688: ffmpeg - A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 ... A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code. Scope: local bookworm: resolved (fixed in 7:4.4-5) bullseye: resolved (fixed in 7:4.3.3-0+deb11u1) forky: resolved (fixed in 7:4.4-5) sid: resolved (fixed in 7:4.4-5) trixie: resolved (fixed in 7:4.4-5)
debian
CVE-2020-22022P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22022 [HIGH] CVE-2020-22022: ffmpeg - A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame ... A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7
debian
CVE-2020-22031P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22031 [HIGH] CVE-2020-22031: ffmpeg - A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/v... A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_w3fdif.c in filter16_complex_low, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed
debian
CVE-2020-22016P3HIGHCVSS 8.8fixed in ffmpeg 7:4.2.2-1 (bookworm)2020
CVE-2020-22016 [HIGH] CVE-2020-22016: ffmpeg - A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.... A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.h when writing .mov files, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.2.2-1) bullseye: resolved (fixed in 7:4.2.2-1) forky: resolved (fixed in 7:4.2.2-1) sid: resolved (fixed in 7:4.2.2-1) trixie: resolved (fixed i
debian
CVE-2022-48434P3HIGHCVSS 8.1fixed in ffmpeg 7:5.1.2-1 (bookworm)2022
CVE-2022-48434 [HIGH] CVE-2022-48434: ffmpeg - libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other prod... libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used). Scope: local bookworm: resolved (fixed in 7:5.1.2
debian
Debian Ffmpeg vulnerabilities | cvebase