cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 6 of 19
CVE-2022-2566P3CRITICALCVSS 9.0fixed in ffmpeg 7:5.1.1-1 (bookworm)2022
CVE-2022-2566 [CRITICAL] CVE-2022-2566: ffmpeg - A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size c... A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc()`. An attacker can cause remote code execution via a ma
debian
CVE-2012-2777P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2777 [CRITICAL] CVE-2012-2777: ffmpeg - Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in ... Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to "width/height changing in CAVS," a different vulnerability than CVE-2012-2784. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2
debian
CVE-2012-2784P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2784 [CRITICAL] CVE-2012-2784: ffmpeg - Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in ... Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to "width/height changing in CAVS," a different vulnerability than CVE-2012-2777. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2
debian
CVE-2012-2779P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2779 [CRITICAL] CVE-2012-2779: ffmpeg - Unspecified vulnerability in the decode_frame function in libavcodec/indeo5.c in... Unspecified vulnerability in the decode_frame function in libavcodec/indeo5.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an invalid "gop header" and decoding in a "half initialized context." Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1)
debian
CVE-2012-2776P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2776 [CRITICAL] CVE-2012-2776: ffmpeg - Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.... Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to an "out of picture write." Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2
debian
CVE-2012-2804P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2804 [CRITICAL] CVE-2012-2804: ffmpeg - Unspecified vulnerability in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav... Unspecified vulnerability in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors, related to "reallocation code" and the luma height and width. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in 7:2.4.1-1) t
debian
CVE-2012-2772P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2772 [CRITICAL] CVE-2012-2772: ffmpeg - Unspecified vulnerability in the ff_rv34_decode_frame function in libavcodec/rv3... Unspecified vulnerability in the ff_rv34_decode_frame function in libavcodec/rv34.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to "width/height changing with frame threading." Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (f
debian
CVE-2020-35965P3HIGHCVSS 7.5fixed in ffmpeg 7:4.3.1-6 (bookworm)2020
CVE-2020-35965 [HIGH] CVE-2020-35965: ffmpeg - decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write beca... decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations. Scope: local bookworm: resolved (fixed in 7:4.3.1-6) bullseye: resolved (fixed in 7:4.3.1-6) forky: resolved (fixed in 7:4.3.1-6) sid: resolved (fixed in 7:4.3.1-6) trixie: resolved (fixed in 7:4.3.1-6)
debian
CVE-2017-9051P3LOWCVSS 9.8fixed in ffmpeg 7:2.6.1-1 (bookworm)2017
CVE-2017-9051 [CRITICAL] CVE-2017-9051: ffmpeg - libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer... libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c. Scope: local bookworm: resolved (fixed in 7:2.6.1-1) bullseye: resolved (fixed in 7:2.6.1-1) forky: resolved (fixed in 7:2.6.1-1) sid: resolved (fixed in 7:2.6.1-1) trixie: resolved (fixed in 7:2.6.1-1)
debian
CVE-2015-8662P3HIGHCVSS 7.3fixed in ffmpeg 7:2.8.4-1 (bookworm)2015
CVE-2015-8662 [HIGH] CVE-2015-8662: ffmpeg - The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 do... The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does not validate the number of decomposition levels before proceeding with Discrete Wavelet Transform decoding, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data. Scope: local bookworm:
debian
CVE-2024-31578P3HIGHCVSS 7.5fixed in ffmpeg 7:4.3.8-0+deb11u1 (bullseye)2024
CVE-2024-31578 [HIGH] CVE-2024-31578: ffmpeg - FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av... FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function. Scope: local bookworm: open bullseye: resolved (fixed in 7:4.3.8-0+deb11u1) forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2013-0856P3CRITICALCVSS 9.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2013
CVE-2013-0856 [CRITICAL] CVE-2013-0856: ffmpeg - The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows rem... The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nb_samples value. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fixed in 7:2.4.1-1) sid: resolved (fixed in
debian
CVE-2016-2327P3HIGHCVSS 8.8fixed in ffmpeg 2.8.5-1 (bookworm)2016
CVE-2016-2327 [HIGH] CVE-2016-2327: ffmpeg - libavcodec/pngenc.c in FFmpeg before 2.8.5 uses incorrect line sizes in certain ... libavcodec/pngenc.c in FFmpeg before 2.8.5 uses incorrect line sizes in certain row calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .avi file, related to the apng_encode_frame and encode_apng functions. Scope: local bookworm: resolved (fixed in 2.8.5-1) bullsey
debian
CVE-2016-2329P3HIGHCVSS 8.8fixed in ffmpeg 2.8.6-1 (bookworm)2016
CVE-2016-2329 [HIGH] CVE-2016-2329: ffmpeg - libavcodec/tiff.c in FFmpeg before 2.8.6 does not properly validate RowsPerStrip... libavcodec/tiff.c in FFmpeg before 2.8.6 does not properly validate RowsPerStrip values and YCbCr chrominance subsampling factors, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted TIFF file, related to the tiff_decode_tag and decode_frame functions. Scope: local bookworm: res
debian
CVE-2017-15672P3HIGHCVSS 8.8fixed in ffmpeg 7:3.4-1 (bookworm)2017
CVE-2017-15672 [HIGH] CVE-2017-15672: ffmpeg - The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and pos... The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via a crafted MP4 file, which triggers an out-of-bounds read. Scope: local bookworm: resolved (fixed in 7:3.4-1) bullseye: resolved (fixed in 7:3.4-1) forky: resolved (fixed in 7:3.4-1) sid: resolved (fixed in 7:3.4-1) trixi
debian
CVE-2018-9841P3LOWCVSS 8.8fixed in ffmpeg 7:3.4.3-1 (bookworm)2018
CVE-2018-9841 [HIGH] CVE-2018-9841: ffmpeg - The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows... The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a long filename. Scope: local bookworm: resolved (fixed in 7:3.4.3-1) bullseye: resolved (fixed in 7:3.4.3-1) forky: resolved (fixed in 7:3.4.3-1) sid: resolved (fixed in 7:3.4
debian
CVE-2016-1897P3MEDIUMCVSS 5.5fixed in ffmpeg 7:2.8.5-1 (bookworm)2016
CVE-2016-1897 [MEDIUM] CVE-2016-1897: ffmpeg - FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbi... FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file. Scope: local bookworm: resolved (fixed in 7:2.8.5-1) bullseye: resolved (fixed in 7:2.8.5-1) forky: reso
debian
CVE-2009-4631P3CRITICALCVSS 9.3fixed in ffmpeg 4:0.5+svn20090706-3 (bookworm)2009
CVE-2009-4631 [CRITICAL] CVE-2009-4631: ffmpeg - Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attacker... Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted VP3 file that triggers an out-of-bounds read and possibly memory corruption. Scope: local bookworm: resolved (fixed in 4:0.5+svn20090706-3) bullseye: resolved (fixed in 4:0.5+svn20090706-3) forky: resolved
debian
CVE-2012-2775P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2775 [CRITICAL] CVE-2012-2775: ffmpeg - Unspecified vulnerability in the read_var_block_data function in libavcodec/alsd... Unspecified vulnerability in the read_var_block_data function in libavcodec/alsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to a large order and an "out of array write in quant_cof." Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky:
debian
CVE-2012-2788P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2788 [CRITICAL] CVE-2012-2788: ffmpeg - Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.... Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array read" when a "packet is shrunk." Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved
debian
Debian Ffmpeg vulnerabilities | cvebase