cbcvebase.

Debian Ffmpeg vulnerabilities

375 known vulnerabilities affecting debian/ffmpeg.

Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80

Vulnerabilities

Page 9 of 19
CVE-2017-11684P3HIGHCVSS 7.5fixed in ffmpeg 7:2.3.1-1 (bookworm)2017
CVE-2017-11684 [HIGH] CVE-2017-11684: ffmpeg - There is an illegal address access in the build_table function in libavcodec/bit... There is an illegal address access in the build_table function in libavcodec/bitstream.c of Libav 12.1 that will lead to remote denial of service via crafted input. Scope: local bookworm: resolved (fixed in 7:2.3.1-1) bullseye: resolved (fixed in 7:2.3.1-1) forky: resolved (fixed in 7:2.3.1-1) sid: resolved (fixed in 7:2.3.1-1) trixie: resolved (fixed in 7:2.3.1-1)
debian
CVE-2023-51793P3HIGHCVSS 7.8fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2023
CVE-2023-51793 [HIGH] CVE-2023-51793: ffmpeg - Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att... Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane. Scope: local bookworm: resolved (fixed in 7:5.1.5-0+deb12u1) bullseye: resolved (fixed in 7:4.3.7-0+deb11u1) forky: resolved (fixed in 7:7.0.1-3) sid: resolved (fixed in 7:7.0.1-3) trixie: resolved (fi
debian
CVE-2006-4800P3HIGHCVSS 7.5fixed in ffmpeg 0.cvs20060329-1 (bookworm)2006
CVE-2006-4800 [HIGH] CVE-2006-4800: ffmpeg - Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow r... Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c
debian
CVE-2014-8547P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.3-1 (bookworm)2014
CVE-2014-8547 [HIGH] CVE-2014-8547: ffmpeg - libavcodec/gifdec.c in FFmpeg before 2.4.2 does not properly compute image heigh... libavcodec/gifdec.c in FFmpeg before 2.4.2 does not properly compute image heights, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted GIF data. Scope: local bookworm: resolved (fixed in 7:2.4.3-1) bullseye: resolved (fixed in 7:2.4.3-1) forky: resolved (fixed in 7:2.4.3-1) sid: resolv
debian
CVE-2017-16803P4HIGHCVSS 7.5fixed in ffmpeg 7:2.2.1-1 (bookworm)2017
CVE-2017-16803 [HIGH] CVE-2017-16803: ffmpeg - In Libav through 11.11 and 12.x through 12.1, the smacker_decode_tree function i... In Libav through 11.11 and 12.x through 12.1, the smacker_decode_tree function in libavcodec/smacker.c does not properly restrict tree recursion, which allows remote attackers to cause a denial of service (bitstream.c:build_table() out-of-bounds read and application crash) via a crafted Smacker stream. Scope: local bookworm: resolved (fixed in 7:2.2.1-1) bullseye: re
debian
CVE-2011-3929P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3929 [MEDIUM] CVE-2011-3929: ffmpeg - The avpriv_dv_produce_packet function in libavcodec in FFmpeg 0.7.x before 0.7.1... The avpriv_dv_produce_packet function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly execute arbitrary code via a crafted DV file. Scope:
debian
CVE-2016-6920P4HIGHCVSS 7.5fixed in ffmpeg 7:3.1.3-1 (bookworm)2016
CVE-2016-6920 [HIGH] CVE-2016-6920: ffmpeg - Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in F... Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of service (application crash) via vectors involving tile positions. Scope: local bookworm: resolved (fixed in 7:3.1.3-1) bullseye: resolved (fixed in 7:3.1.3-1) forky: resolved (fixed in 7:3.1.3-1) sid: resolved (fixed in 7:3.1.3
debian
CVE-2017-9991P4HIGHCVSS 7.8fixed in ffmpeg 7:3.2.5-1 (bookworm)2017
CVE-2017-9991 [HIGH] CVE-2017-9991: ffmpeg - Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec... Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file. Scope: local bookworm: resolved (fixed in 7:3
debian
CVE-2012-0853P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2012
CVE-2012-0853 [MEDIUM] CVE-2012-0853: ffmpeg - The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec... The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec in FFmpeg 0.7.x before 0.7.12, and 0.8.x before 0.8.11; and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (infinite loop and crash) and possibly execute arbitrary code via a large component
debian
CVE-2016-6671P3HIGHCVSS 7.8fixed in ffmpeg 7:3.1.2-1 (bookworm)2016
CVE-2016-6671 [HIGH] CVE-2016-6671: ffmpeg - The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows rem... The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted SWF file. Scope: local bookworm: resolved (fixed in 7:3.1.2-1) bullseye: resolved (fixed in 7:3.1.2-1) forky: resolved (fixed in 7:3.1.2-1) sid: resolved (fixed in 7:3.1.2-1) trixie: resol
debian
CVE-2015-6823P4HIGHCVSS 7.5fixed in ffmpeg 7:2.7.2-1 (bookworm)2015
CVE-2015-6823 [HIGH] CVE-2015-6823: ffmpeg - The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does n... The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does not initialize certain context data, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact via crafted Apple Lossless Audio Codec (ALAC) data. Scope: local bookworm: resolved (fixed in 7:2.7.2-1) bullseye: resolved (fixe
debian
CVE-2015-6818P4HIGHCVSS 7.5fixed in ffmpeg 7:2.7.2-1 (bookworm)2015
CVE-2015-6818 [HIGH] CVE-2015-6818: ffmpeg - The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 doe... The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted image with two or more of these chunks. Scope: local bookworm: resolv
debian
CVE-2015-8217P4HIGHCVSS 7.5fixed in ffmpeg 7:2.8.2-1 (bookworm)2015
CVE-2015-8217 [HIGH] CVE-2015-8217: ffmpeg - The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 do... The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted High Efficiency Video Coding (HEVC) data. Scope: local bookworm: resolved (fixed in 7:2.8.2-1) bullseye:
debian
CVE-2014-8541P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.3-1 (bookworm)2014
CVE-2014-8541 [HIGH] CVE-2014-8541: ffmpeg - libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension difference... libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension differences, and not bits-per-pixel differences, when determining whether an image size has changed, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MJPEG data. Scope: local bookworm: resolved (fixed in 7:2.4.3-1)
debian
CVE-2014-8549P4HIGHCVSS 7.5fixed in ffmpeg 7:2.4.3-1 (bookworm)2014
CVE-2014-8549 [HIGH] CVE-2014-8549: ffmpeg - libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of chan... libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of channels to at most 2, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted On2 data. Scope: local bookworm: resolved (fixed in 7:2.4.3-1) bullseye: resolved (fixed in 7:2.4.3-1) forky: resolved (fixed in 7:2.4.3
debian
CVE-2014-9318P4HIGHCVSS 7.5fixed in ffmpeg 2.4.4-1 (bookworm)2014
CVE-2014-9318 [HIGH] CVE-2014-9318: ffmpeg - The raw_decode function in libavcodec/rawdec.c in FFMpeg before 2.1.6, 2.2.x thr... The raw_decode function in libavcodec/rawdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via a crafted .cine file that triggers the avpicture_get_size function to return a negative frame size. Scope: local bookworm: resol
debian
CVE-2011-3947P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-3947 [MEDIUM] CVE-2011-3947: ffmpeg - Buffer overflow in mjpegbdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0... Buffer overflow in mjpegbdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MJPEG-B file. Scope: local bookworm: resolved (fixed in 7:2.4
debian
CVE-2015-8219P4HIGHCVSS 7.5fixed in ffmpeg 7:2.8.2-1 (bookworm)2015
CVE-2015-8219 [HIGH] CVE-2015-8219: ffmpeg - The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does n... The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordinates, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data. Scope: local bookworm: resolved (fixed in 7:2.8.2-1) bull
debian
CVE-2022-3109P4HIGHCVSS 7.5fixed in ffmpeg 7:5.1-1 (bookworm)2022
CVE-2022-3109 [HIGH] CVE-2022-3109: ffmpeg - An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavco... An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability. Scope: local bookworm: resolved (fixed in 7:5.1-1) bullseye: resolved (fixed in 7:4.3.6-0+deb11u1) forky: resolved (fixed in 7:5.1-1) sid: resolved (fixed in 7:5.1-1)
debian
CVE-2020-20451P4LOWCVSS 7.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-20451 [HIGH] CVE-2020-20451: ffmpeg - Denial of Service issue in FFmpeg 4.2 due to resource management errors via ffto... Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c. Scope: local bookworm: resolved (fixed in 7:4.3-2) bullseye: resolved (fixed in 7:4.3-2) forky: resolved (fixed in 7:4.3-2) sid: resolved (fixed in 7:4.3-2) trixie: resolved (fixed in 7:4.3-2)
debian
Debian Ffmpeg vulnerabilities | cvebase