cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 5 of 19
CVE-2013-0865P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0865 [CRITICAL] CVE-2013-0865: ffmpeg - The vqa_decode_chunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 an... The vqa_decode_chunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large (1) cbp0 or (2) cbpz chunk in Westwood Studios VQA Video file, which triggers an out-of-bounds write. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky
debian
CVE-2019-11339P3HIGHCVSS 8.8fixed in ffmpeg 7:4.1.3-1 (bookworm)2019
CVE-2019-11339 [HIGH] CVE-2019-11339: ffmpeg - The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.... The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via crafted MPEG-4 video data. Scope: local bookworm: resolved (fixed in 7:4.1.3-1) bullseye: resolved (fixed in 7:4.1.3-1) forky: resolved (fixed
debian
CVE-2017-14169P3LOWCVSS 8.8fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14169 [HIGH] CVE-2017-14169: ffmpeg - In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> ... In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided. As a result, the variable "item_num" turns negative, bypassing the check for a large value. Scope: local bookworm: resolved (fixed in 7:3.3.4-1) bullsey
debian
CVE-2017-14225P3LOWCVSS 8.8fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14225 [HIGH] CVE-2017-14225: ffmpeg - The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may ... The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dere
debian
CVE-2023-6605P3HIGHCVSS 7.2fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2023
CVE-2023-6605 [HIGH] CVE-2023-6605: ffmpeg - A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows ar... A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs. Scope: local bookworm: resolved (fixed in 7:5.1.7-0+deb12u1) bullseye: resolved (fixed in 7:4.3.9-0+deb11u1) forky: resolved (fixed in 7:7.1.1-1) sid: resolved
debian
CVE-2015-8663P3HIGHCVSS 8.3fixed in ffmpeg 7:2.8.4-1 (bookworm)2015
CVE-2015-8663 [HIGH] CVE-2015-8663: ffmpeg - The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserve... The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file. Scope: local bookworm: resolved (fixed in 7:2.8.4-1) bullseye: resolved (fixed in 7:2.8.4-1)
debian
CVE-2012-5361P3HIGHCVSS 7.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-5361 [HIGH] CVE-2012-5361: ffmpeg - Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary co... Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved (fixed in 7:2.4.1-1)
debian
CVE-2025-59732P3HIGHCVSS 8.7fixed in ffmpeg 7:5.1.7-0+deb12u1 (bookworm)2025
CVE-2025-59732 [HIGH] CVE-2025-59732: ffmpeg - When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an imp... When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that the height and width are divisible by 8. If the height or width of the image is not divisible by 8, the copy loops at [0] and [1] will continue to write until the next multiple of 8. The buffer td->uncompressed_data is allocated in decode_block based on the precise h
debian
CVE-2013-0846P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0846 [CRITICAL] CVE-2013-0846: ffmpeg - Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c i... Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted QDM2 data, which triggers an out-of-bounds array access. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved
debian
CVE-2012-2773P3CRITICALCVSS 9.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2773 [CRITICAL] CVE-2012-2773: ffmpeg - Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack ... Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2781. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved (
debian
CVE-2012-2781P3CRITICALCVSS 9.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2781 [CRITICAL] CVE-2012-2781: ffmpeg - Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack ... Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2780. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved (
debian
CVE-2012-2778P3CRITICALCVSS 9.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2778 [CRITICAL] CVE-2012-2778: ffmpeg - Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack ... Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2780, and CVE-2012-2781. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved (
debian
CVE-2012-2780P3CRITICALCVSS 9.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2780 [CRITICAL] CVE-2012-2780: ffmpeg - Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack ... Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2781. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) trixie: resolved (
debian
CVE-2023-50010P3HIGHCVSS 7.8fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2023
CVE-2023-50010 [HIGH] CVE-2023-50010: ffmpeg - FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_mo... FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component. Scope: local bookworm: resolved (fixed in 7:5.1.5-0+deb12u1) bullseye: resolved (fixed in 7:4.3.7-0+deb11u1) forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trix
debian
CVE-2025-63757P3HIGHCVSS 7.5fixed in ffmpeg 7:5.1.8-0+deb12u1 (bookworm)2025
CVE-2025-63757 [HIGH] CVE-2025-63757: ffmpeg - Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswsca... Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0. Scope: local bookworm: resolved (fixed in 7:5.1.8-0+deb12u1) bullseye: resolved (fixed in 7:4.3.9-0+deb11u2) forky: resolved (fixed in 7:7.1.3-1) sid: resolved (fixed in 7:7.1.3-1) trixie: resolved (fixed in 7:7.1.3-0+deb13u1)
debian
CVE-2017-9992P3HIGHCVSS 8.8fixed in ffmpeg 7:3.2.5-1 (bookworm)2017
CVE-2017-9992 [HIGH] CVE-2017-9992: ffmpeg - Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FF... Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file. Scope: local bookworm: resolved (fixed in 7:3.2.5-1)
debian
CVE-2017-14767P3HIGHCVSS 8.8fixed in ffmpeg 7:3.3.4-1 (bookworm)2017
CVE-2017-14767 [HIGH] CVE-2017-14767: ffmpeg - The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg b... The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allows remote attackers to cause a denial of service (heap buffer overflow) or possibly have unspecified other impact via a crafted sdp file. Scope: local bookworm: resolved (fixed in 7:3.3.4-1) bullseye: resolved (fixed in 7
debian
CVE-2016-2330P3HIGHCVSS 8.8fixed in ffmpeg 2.8.6-1 (bookworm)2016
CVE-2016-2330 [HIGH] CVE-2016-2330: ffmpeg - libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer siz... libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .tga file, related to the gif_image_write_image, gif_encode_init, and gif_encode_close functions. Scope: local bookworm: resolved (fixed in 2.8.
debian
CVE-2019-11338P3HIGHCVSS 8.8fixed in ffmpeg 7:4.1.3-1 (bookworm)2019
CVE-2019-11338 [HIGH] CVE-2019-11338: ffmpeg - libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate f... libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data. Scope: local bookworm: resolved (fixed in 7:4.1.3-1) bullseye: resolved (fixed in 7:4.1.3-1) forky: r
debian
CVE-2016-5199P3HIGHCVSS 8.8fixed in ffmpeg 7:3.2-1 (bookworm)2016
CVE-2016-5199 [HIGH] CVE-2016-5199: ffmpeg - An off by one error resulting in an allocation of zero size in FFmpeg in Google ... An off by one error resulting in an allocation of zero size in FFmpeg in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted video file. Scope: local bookworm: resolved (fixed in 7:3.2-1) bullseye: resolved (fix
debian
Debian Ffmpeg vulnerabilities | cvebase