Debian Ffmpeg vulnerabilities
375 known vulnerabilities affecting debian/ffmpeg.
Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80
Vulnerabilities
Page 4 of 19
CVE-2013-0873P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0873 [CRITICAL] CVE-2013-0873: ffmpeg - The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows r...
The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel count, related to "freeing invalid addresses."
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie
debian
CVE-2013-0869P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0869 [CRITICAL] CVE-2013-0869: ffmpeg - The field_end function in libavcodec/h264.c in FFmpeg before 1.1.2 allows remote...
The field_end function in libavcodec/h264.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted H.264 data, related to an SPS and slice mismatch and an out-of-bounds array access.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed
debian
CVE-2013-0850P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0850 [CRITICAL] CVE-2013-0850: ffmpeg - The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1 allow...
The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted H.264 data, which triggers an out-of-bounds array access.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
tri
debian
CVE-2008-4610P4LOWCVSS 4.3PoCfixed in ffmpeg 7:2.4.1-1 (bookworm)2008
CVE-2008-4610 [MEDIUM] CVE-2008-4610: ffmpeg - MPlayer allows remote attackers to cause a denial of service (application crash)...
MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than CVE-2007-6718.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fi
debian
CVE-2013-0854P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0854 [CRITICAL] CVE-2013-0854: ffmpeg - The mjpeg_decode_scan_progressive_ac function in libavcodec/mjpegdec.c in FFmpeg...
The mjpeg_decode_scan_progressive_ac function in libavcodec/mjpegdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted MJPEG data.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4
debian
CVE-2013-0849P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0849 [CRITICAL] CVE-2013-0849: ffmpeg - The roq_decode_init function in libavcodec/roqvideodec.c in FFmpeg before 1.1 al...
The roq_decode_init function in libavcodec/roqvideodec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted (1) width or (2) height dimension that is not a multiple of sixteen in id RoQ video data.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
s
debian
CVE-2023-50008P3HIGHCVSS 7.8fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2023
CVE-2023-50008 [HIGH] CVE-2023-50008: ffmpeg - FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrec...
FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.
Scope: local
bookworm: resolved (fixed in 7:5.1.7-0+deb12u1)
bullseye: resolved
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2013-0867P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0867 [CRITICAL] CVE-2013-0867: ffmpeg - The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 doe...
The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remote attackers to have unspecified impact via crafted H.264 video data, related to an out-of-bounds array access.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolv
debian
CVE-2013-0848P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0848 [CRITICAL] CVE-2013-0848: ffmpeg - The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows rem...
The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted width in huffyuv data with the predictor set to median and the colorspace set to YUV422P, which triggers an out-of-bounds array access.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
debian
CVE-2018-13302P3HIGHCVSS 8.8fixed in ffmpeg 7:3.4.3-1 (bookworm)2018
CVE-2018-13302 [HIGH] CVE-2018-13302: ffmpeg - In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_IN...
In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independent substreams in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4, leading to a denial of service or possibly unspecified other impact.
Scope: local
bookworm: resolved (f
debian
CVE-2005-4048P3MEDIUMCVSS 7.5fixed in ffmpeg 0.cvs20050918-5.1 (bookworm)2005
CVE-2005-4048 [HIGH] CVE-2005-4048: ffmpeg - Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) ...
Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.
Scope: local
bookworm: resolved (fixed in 0.cvs20050918-5.1)
bullseye:
debian
CVE-2008-4866P3CRITICALCVSS 10.0fixed in ffmpeg 0.svn20080206-14 (bookworm)2008
CVE-2008-4866 [CRITICAL] CVE-2008-4866: ffmpeg - Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, ...
Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY.
Scope: local
bookworm: resolved (fixed in 0.svn20080206-14)
bullseye: resolved (fixed in 0.svn20080206-14)
debian
CVE-2024-35367P3CRITICALCVSS 9.1fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2024
CVE-2024-35367 [CRITICAL] CVE-2024-35367: ffmpeg - FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, sta...
FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer
Scope: local
bookworm: resolved (fixed in 7:5.1.7-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.8-0+deb11u2)
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2015-8661P3HIGHCVSS 8.3fixed in ffmpeg 7:2.8.3-1 (bookworm)2015
CVE-2015-8661 [HIGH] CVE-2015-8661: ffmpeg - The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before ...
The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before 2.8.3 does not validate the relationship between the number of threads and the number of slices, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted H.264 data.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2025-59733P3HIGHCVSS 8.7fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2025
CVE-2025-59733 [HIGH] CVE-2025-59733: ffmpeg - When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an imp...
When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that all image channels have the same pixel type (and size), and that if there are four channels, the first four are "B", "G", "R" and "A". The channel parsing code can be found in decode_header. The buffer td->uncompressed_data is allocated in decode_block based on the x
debian
CVE-2013-0868P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0868 [CRITICAL] CVE-2013-0868: ffmpeg - libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have a...
libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted Huffyuv data, related to an out-of-bounds write and (1) unchecked return codes from the init_vlc function and (2) "len==0 cases."
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4
debian
CVE-2010-3429P3MEDIUMCVSS 6.8fixed in ffmpeg 4:0.5.2-6 (bookworm)2010
CVE-2010-3429 [MEDIUM] CVE-2010-3429: ffmpeg - flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and othe...
flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability."
Scope: local
bookworm: resolved (fixed in 4:0.5.2-6)
bullseye: resolved (fixed in 4:0.5.2-6)
forky: resolved (fixed in 4:0.5.2-6)
sid: resolve
debian
CVE-2023-50009P3LOWCVSS 8.0fixed in ffmpeg 7:7.0.1-3 (forky)2023
CVE-2023-50009 [HIGH] CVE-2023-50009: ffmpeg - FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gauss...
FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2012-2771P3CRITICALCVSS 9.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2771 [CRITICAL] CVE-2012-2771: ffmpeg - Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack ...
Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2773, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2781.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (
debian
CVE-2013-0844P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0844 [CRITICAL] CVE-2013-0844: ffmpeg - Off-by-one error in the adpcm_decode_frame function in libavcodec/adpcm.c in FFm...
Off-by-one error in the adpcm_decode_frame function in libavcodec/adpcm.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via crafted DK4 data, which triggers an out-of-bounds array access.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fix
debian