Debian Ffmpeg vulnerabilities
375 known vulnerabilities affecting debian/ffmpeg.
Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80
Vulnerabilities
Page 7 of 19
CVE-2018-15822P3LOWCVSS 7.5fixed in ffmpeg 7:4.0.3-1 (bookworm)2018
CVE-2018-15822 [HIGH] CVE-2018-15822: ffmpeg - The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does...
The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.
Scope: local
bookworm: resolved (fixed in 7:4.0.3-1)
bullseye: resolved (fixed in 7:4.0.3-1)
forky: resolved (fixed in 7:4.0.3-1)
sid: resolved (fixed in 7:4.0.3-1)
trixie: resolved (fixed in 7:4.0.3-1)
debian
CVE-2012-0947P3MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-0947 [MEDIUM] CVE-2012-0947: ffmpeg - Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vq...
Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo.c) in libavcodec in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VQA media file in which the image size is not a multiple of th
debian
CVE-2012-2797P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2797 [CRITICAL] CVE-2012-2797: ffmpeg - Unspecified vulnerability in the decode_frame_mp3on4 function in libavcodec/mpeg...
Unspecified vulnerability in the decode_frame_mp3on4 function in libavcodec/mpegaudiodec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors related to a calculation that prevents a frame from being "large enough."
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fix
debian
CVE-2021-38291P3LOWCVSS 7.5fixed in ffmpeg 7:4.4.1-1 (bookworm)2021
CVE-2021-38291 [HIGH] CVE-2021-38291: ffmpeg - FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers fro...
FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.
Scope: local
bookworm: resolved (fixed in 7:4.4.1-1)
bullseye: resolved (fixed in 7:4.3.3-0+deb11u1)
forky: resolved (fixed in 7:4.4.1-1)
sid: resolved (fixed in 7:4.4.1-1)
trixie: resolved (fixed in 7:4.4.1-1)
debian
CVE-2011-2162P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-2162 [CRITICAL] CVE-2011-2162: ffmpeg - Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in M...
Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5 (aka MES5) have unknown impact and attack vectors, related to issues "originally discovered by Google Chrome developers."
Scope: local
bookworm
debian
CVE-2020-21041P3HIGHCVSS 7.5fixed in ffmpeg 7:4.3.2-0+deb11u2 (bookworm)2020
CVE-2020-21041 [HIGH] CVE-2020-21041: ffmpeg - Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in ...
Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service
Scope: local
bookworm: resolved (fixed in 7:4.3.2-0+deb11u2)
bullseye: resolved (fixed in 7:4.3.2-0+deb11u2)
forky: resolved (fixed in 7:4.3.2-0+deb11u2)
sid: resolved (fixed in 7:4.3.2-0+deb11u2)
trixi
debian
CVE-2019-17539P3LOWCVSS 9.8fixed in ffmpeg 7:4.2.1-1 (bookworm)2019
CVE-2019-17539 [CRITICAL] CVE-2019-17539: ffmpeg - In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer ...
In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.
Scope: local
bookworm: resolved (fixed in 7:4.2.1-1)
bullseye: resolved (fixed in 7:4.2.1-1)
forky: resolved (fixed in 7:4.2.1-1)
sid: resolved (fixed in 7:4.2.1-1)
trixie: resolved (fixed
debian
CVE-2024-32230P3HIGHCVSS 7.8fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2024
CVE-2024-32230 [HIGH] CVE-2024-32230: ffmpeg - FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug ...
FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0
Scope: local
bookworm: resolved (fixed in 7:5.1.5-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.7-0+deb11u1)
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolved (fixed in 7:7.0.1-
debian
CVE-2011-2160P3MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-2160 [MEDIUM] CVE-2011-2160: ffmpeg - The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and o...
The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (f
debian
CVE-2016-2326P3HIGHCVSS 8.8fixed in ffmpeg 2.8.5-1 (bookworm)2016
CVE-2016-2326 [HIGH] CVE-2016-2326: ffmpeg - Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFm...
Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PTS (aka presentation timestamp) value in a .mov file.
Scope: local
bookworm: resolved (fixed in 2.8.5-1)
bullseye: resolved (fixed in 2.8.5-1)
forky: resolved (fixe
debian
CVE-2022-3965P3MEDIUMCVSS 4.3fixed in ffmpeg 7:5.1.3-1 (bookworm)2022
CVE-2022-3965 [MEDIUM] CVE-2022-3965: ffmpeg - A vulnerability classified as problematic was found in ffmpeg. This vulnerabilit...
A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b3
debian
CVE-2021-38092P3LOWCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2021
CVE-2021-38092 [HIGH] CVE-2021-38092: ffmpeg - Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_conv...
Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:
debian
CVE-2021-38093P3LOWCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2021
CVE-2021-38093 [HIGH] CVE-2021-38093: ffmpeg - Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convo...
Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4
debian
CVE-2021-38094P3LOWCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2021
CVE-2021-38094 [HIGH] CVE-2021-38094: ffmpeg - Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convol...
Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.
debian
CVE-2021-38090P3LOWCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2021
CVE-2021-38090 [HIGH] CVE-2021-38090: ffmpeg - Integer Overflow vulnerability in function filter16_roberts in libavfilter/vf_co...
Integer Overflow vulnerability in function filter16_roberts in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in
debian
CVE-2021-38091P3LOWCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2021
CVE-2021-38091 [HIGH] CVE-2021-38091: ffmpeg - Integer Overflow vulnerability in function filter16_sobel in libavfilter/vf_conv...
Integer Overflow vulnerability in function filter16_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:
debian
CVE-2020-20898P3LOWCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-20898 [HIGH] CVE-2020-20898: ffmpeg - Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_co...
Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in
debian
CVE-2020-20891P3HIGHCVSS 8.8fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-20891 [HIGH] CVE-2020-20891: ffmpeg - Buffer Overflow vulnerability in function config_input in libavfilter/vf_gblur.c...
Buffer Overflow vulnerability in function config_input in libavfilter/vf_gblur.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2012-2803P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2803 [CRITICAL] CVE-2012-2803: ffmpeg - Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12...
Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to resetting the data size value.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-
debian
CVE-2012-2801P3CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2801 [CRITICAL] CVE-2012-2801: ffmpeg - Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0...
Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to dimensions and "out of array writes."
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2
debian