Debian Ffmpeg vulnerabilities
375 known vulnerabilities affecting debian/ffmpeg.
Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80
Vulnerabilities
Page 8 of 19
CVE-2014-8544P3HIGHCVSS 7.5fixed in ffmpeg 7:2.4.3-1 (bookworm)2014
CVE-2014-8544 [HIGH] CVE-2014-8544: ffmpeg - libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pix...
libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted TIFF data.
Scope: local
bookworm: resolved (fixed in 7:2.4.3-1)
bullseye: resolved (fixed in 7:2.4.3-1)
forky: resolved (fixed in 7:2.4.3-1)
sid
debian
CVE-2008-4867P3CRITICALCVSS 10.0fixed in ffmpeg 0.svn20080206-14 (bookworm)2008
CVE-2008-4867 [CRITICAL] CVE-2008-4867: ffmpeg - Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MP...
Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.
Scope: local
bookworm: resolved (fixed in 0.svn20080206-14)
bullseye: resolved (fixed in 0.svn20080206-14)
forky: resolved (fixed in 0.svn20080206-14)
sid: r
debian
CVE-2011-3941P3HIGHCVSS 7.5fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3941 [HIGH] CVE-2011-3941: ffmpeg - The decode_mb function in libavcodec/error_resilience.c in FFmpeg before 0.10 al...
The decode_mb function in libavcodec/error_resilience.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via vectors related to an uninitialized block index, which triggers an out-of-bounds write.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fi
debian
CVE-2016-1898P3MEDIUMCVSS 5.5fixed in ffmpeg 7:2.8.5-1 (bookworm)2016
CVE-2016-1898 [MEDIUM] CVE-2016-1898: ffmpeg - FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbi...
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.
Scope: local
bookworm: resolved (fixed in 7:2.8.5-1)
bullseye: resolved (fixed in 7:2.8.5-1)
forky:
debian
CVE-2023-49501P3LOWCVSS 8.0fixed in ffmpeg 7:7.0.1-3 (forky)2023
CVE-2023-49501 [HIGH] CVE-2023-49501: ffmpeg - Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local atta...
Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolved (fixed in 7:7.0.1-3)
debian
CVE-2023-51795P3HIGHCVSS 8.0fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2023
CVE-2023-51795 [HIGH] CVE-2023-51795: ffmpeg - Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame
Scope: local
bookworm: resolved (fixed in 7:5.1.5-0+deb12u1)
bullseye: resolved
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolve
debian
CVE-2023-51798P3HIGHCVSS 7.8fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2023
CVE-2023-51798 [HIGH] CVE-2023-51798: ffmpeg - Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.
Scope: local
bookworm: resolved (fixed in 7:5.1.5-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.7-0+deb11u1)
forky: resolved (fixed in 7:7.0.1-3)
sid: resolv
debian
CVE-2016-2328P3HIGHCVSS 8.8fixed in ffmpeg 2.8.6-1 (bookworm)2016
CVE-2016-2328 [HIGH] CVE-2016-2328: ffmpeg - libswscale/swscale_unscaled.c in FFmpeg before 2.8.6 does not validate certain h...
libswscale/swscale_unscaled.c in FFmpeg before 2.8.6 does not validate certain height values, which allows remote attackers to cause a denial of service (out-of-bounds array read access) or possibly have unspecified other impact via a crafted .cine file, related to the bayer_to_rgb24_wrapper and bayer_to_yv12_wrapper functions.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2011-3946P3LOWCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3946 [MEDIUM] CVE-2011-3946: ffmpeg - The ff_h264_decode_sei function in libavcodec/h264_sei.c in FFmpeg before 0.10 a...
The ff_h264_decode_sei function in libavcodec/h264_sei.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Supplemental enhancement information (SEI) data, which triggers an infinite loop.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolve
debian
CVE-2018-13300P3HIGHCVSS 8.1fixed in ffmpeg 7:3.4.3-1 (bookworm)2018
CVE-2018-13300 [HIGH] CVE-2018-13300: ffmpeg - In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the ...
In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array read while converting a crafted AVI file to MPEG4, leading to a denial of service and possibly an information disclosure.
Scope: local
bookworm: resolved (fixed in 7:3.4.3-1)
bul
debian
CVE-2012-2783P4CRITICALCVSS 10.0fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2783 [CRITICAL] CVE-2012-2783: ffmpeg - Unspecified vulnerability in libavcodec/vp56.c in FFmpeg before 0.11, and Libav ...
Unspecified vulnerability in libavcodec/vp56.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to "freeing the returned frame."
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
debian
CVE-2014-8543P3HIGHCVSS 7.5fixed in ffmpeg 7:2.4.3-1 (bookworm)2014
CVE-2014-8543 [HIGH] CVE-2014-8543: ffmpeg - libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV I...
libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MM video data.
Scope: local
bookworm: resolved (fixed in 7:2.4.3-1)
bullseye: resolved (fixed in 7:2.4.3-1)
debian
CVE-2017-9996P3HIGHCVSS 7.8fixed in ffmpeg 7:3.2.5-1 (bookworm)2017
CVE-2017-9996 [HIGH] CVE-2017-9996: ffmpeg - The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.1...
The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted fil
debian
CVE-2017-9994P3HIGHCVSS 7.8fixed in ffmpeg 7:3.2.5-1 (bookworm)2017
CVE-2017-9994 [HIGH] CVE-2017-9994: ffmpeg - libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1....
libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the vp8_decode_mb_row_no_
debian
CVE-2015-6826P3HIGHCVSS 7.5fixed in ffmpeg 7:2.7.2-1 (bookworm)2015
CVE-2015-6826 [HIGH] CVE-2015-6826: ffmpeg - The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg befo...
The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via crafted (1) RV30 or (2) RV40 RealVideo data.
Scope: local
bookworm: resolved (fixed in 7:2.7.2-1)
bullsey
debian
CVE-2015-6821P3HIGHCVSS 7.5fixed in ffmpeg 7:2.7.2-1 (bookworm)2015
CVE-2015-6821 [HIGH] CVE-2015-6821: ffmpeg - The ff_mpv_common_init function in libavcodec/mpegvideo.c in FFmpeg before 2.7.2...
The ff_mpv_common_init function in libavcodec/mpegvideo.c in FFmpeg before 2.7.2 does not properly maintain the encoding context, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via crafted MPEG data.
Scope: local
bookworm: resolved (fixed in 7:2.7.2-1)
bullseye: resolved (fixed in 7:2.7.2-1)
debian
CVE-2015-6820P3HIGHCVSS 7.5fixed in ffmpeg 7:2.7.2-1 (bookworm)2015
CVE-2015-6820 [HIGH] CVE-2015-6820: ffmpeg - The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not...
The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted AAC data.
Scope: local
bookworm: resolv
debian
CVE-2014-9603P3HIGHCVSS 7.5fixed in ffmpeg 7:2.5.1-1 (bookworm)2014
CVE-2014-9603 [HIGH] CVE-2014-9603: ffmpeg - The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not...
The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Sierra VMD video data.
Scope: local
bookworm: resolved (fixed in 7:2.5
debian
CVE-2012-2805P3HIGHCVSS 7.5fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-2805 [HIGH] CVE-2012-2805: ffmpeg - Unspecified vulnerability in FFMPEG 0.10 allows remote attackers to cause a deni...
Unspecified vulnerability in FFMPEG 0.10 allows remote attackers to cause a denial of service.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
debian
CVE-2023-49528P3HIGHCVSS 8.0fixed in ffmpeg 7:7.0.1-3 (forky)2023
CVE-2023-49528 [HIGH] CVE-2023-49528: ffmpeg - Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a loc...
Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolved (fixed in 7:7.0.1
debian