cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 3 of 19
CVE-2019-12730P3LOWCVSS 9.8fixed in ffmpeg 7:4.1.4-1 (bookworm)2019
CVE-2019-12730 [CRITICAL] CVE-2019-12730: ffmpeg - aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1... aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables. Scope: local bookworm: resolved (fixed in 7:4.1.4-1) bullseye: resolved (fixed in 7:4.1.4-1) forky: resolved (fixed in 7:4.1.4-1) sid: resolved (fixed in 7:4.1.4-1) trixie: resolved (fixed in
debian
CVE-2009-4634P3CRITICALCVSS 10.0fixed in ffmpeg 4:0.5+svn20090706-3 (bookworm)2009
CVE-2009-4634 [CRITICAL] CVE-2009-4634: ffmpeg - Multiple integer underflows in FFmpeg 0.5 allow remote attackers to cause a deni... Multiple integer underflows in FFmpeg 0.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted file that (1) bypasses a validation check in vorbis_dec.c and triggers a wraparound of the stack pointer, or (2) access a pointer from out-of-bounds memory in mov.c, related to an elst tag that appears before a tag that cre
debian
CVE-2020-14212P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3.1-1 (bookworm)2020
CVE-2020-14212 [HIGH] CVE-2020-14212: ffmpeg - FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavform... FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted. Scope: local bookworm: resolved (fixed in 7:4.3.1-1) bullseye: resolved (fixed in 7:4.3.1-1) forky: resolved (fixed in 7:4.3.1-1) sid: resolved (fixed in 7:4.3.1-1) trixie: resol
debian
CVE-2020-22034P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22034 [HIGH] CVE-2020-22034: ffmpeg - A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_f... A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_floodfill.c, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2023-49502P3HIGHCVSS 8.8fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2023
CVE-2023-49502 [HIGH] CVE-2023-49502: ffmpeg - Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local atta... Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component. Scope: local bookworm: resolved (fixed in 7:5.1.7-0+deb12u1) bullseye: resolved (fixed in 7:4.3.8-0+deb11u1) forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in
debian
CVE-2020-22029P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22029 [HIGH] CVE-2020-22029: ffmpeg - A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/v... A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which crossfade_samples_fltp, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fix
debian
CVE-2011-4351P3HIGHCVSS 7.5fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-4351 [HIGH] CVE-2011-4351: ffmpeg - Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before 0.7.8, ... Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before 0.7.8, and 0.8.x before 0.8.8 allows remote attackers to execute arbitrary code via unspecified vectors. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved (fixed in 7
debian
CVE-2013-0858P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0858 [CRITICAL] CVE-2013-0858: ffmpeg - The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 al... The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed i
debian
CVE-2016-6164P3CRITICALCVSS 9.8fixed in ffmpeg 7:3.1.1-1 (bookworm)2016
CVE-2016-6164 [CRITICAL] CVE-2016-6164: ffmpeg - Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg ... Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving sample size. Scope: local bookworm: resolved (fixed in 7:3.1.1-1) bullseye: resolved (fixed in 7:3.1.1-1) forky: resolved (fixed in 7:3.1.1-1) sid: resolved (
debian
CVE-2020-22027P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22027 [HIGH] CVE-2020-22027: ffmpeg - A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at l... A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighbor.c, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-2
debian
CVE-2020-22023P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22023 [HIGH] CVE-2020-22023: ffmpeg - A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame... A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_bitplanenoise.c, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed
debian
CVE-2020-22017P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22017 [HIGH] CVE-2020-22017: ffmpeg - A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_recta... A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/drawutils.c, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in
debian
CVE-2020-22030P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22030 [HIGH] CVE-2020-22030: ffmpeg - A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/a... A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/af_afade.c in crossfade_samples_fltp, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed
debian
CVE-2024-35365P3LOWCVSS 8.8fixed in ffmpeg 7:7.0.1-3 (forky)2024
CVE-2024-35365 [HIGH] CVE-2024-35365: ffmpeg - FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_... FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2017-16840P3CRITICALCVSS 9.8fixed in ffmpeg 7:3.4.1-1 (bookworm)2017
CVE-2017-16840 [CRITICAL] CVE-2017-16840: ffmpeg - The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers... The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related to libavcodec/vc2enc.c and libavcodec/vc2enc_dwt.c. Scope: local bookworm: resolved (fixed in 7:3.4.1-1) bullseye: resolved (fixed in 7:3.4.1-1) forky: resolved (fixed
debian
CVE-2022-3964P3MEDIUMCVSS 4.3fixed in ffmpeg 7:5.1.3-1 (bookworm)2022
CVE-2022-3964 [MEDIUM] CVE-2022-3964: ffmpeg - A vulnerability classified as problematic has been found in ffmpeg. This affects... A vulnerability classified as problematic has been found in ffmpeg. This affects an unknown part of the file libavcodec/rpzaenc.c of the component QuickTime RPZA Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. It is possible to initiate the attack remotely. The name of the patch is 92f9b28ed84a77138105475beba16c146bdaf984. It is re
debian
CVE-2016-3062P3HIGHCVSS 8.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2016
CVE-2016-3062 [HIGH] CVE-2016-3062: ffmpeg - The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg ... The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1
debian
CVE-2020-22015P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3.2-0+deb11u2 (bookworm)2020
CVE-2020-22015 [HIGH] CVE-2020-22015: ffmpeg - Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the ou... Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code. Scope: local bookworm: resolved (fixed in 7:4.3.2-0+deb11u2) bullseye: resolved (fixed in 7:4.3.2-0+deb11u2) forky: resolved (fi
debian
CVE-2025-9951P3HIGHCVSS 7.2fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2025
CVE-2025-9951 [HIGH] CVE-2025-9951: ffmpeg - A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attack... A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000. Scope: local bookworm: resolved (fixed in 7:5.1.7-0+deb12u1) bullseye: resolved (fixed in 7:4.3.9-0+deb11u2) forky: resolved (fixed in 7:7.1.2-1) sid: resolved (fixed in
debian
CVE-2020-22035P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22035 [HIGH] CVE-2020-22035: ffmpeg - A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row... A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might lead to memory corruption and other potential consequences. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-
debian
Debian Ffmpeg vulnerabilities | cvebase