Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ffmpeg HIGH 7.2
CVE-2023-6605

A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running…

Fix: after 6.0
Fix from $1,950 2025-01-06
Ffmpeg MEDIUM 5.3
CVE-2023-6604

A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded perform…

Fix: after 6.0
Fix from $1,600 2025-01-06
Ffmpeg HIGH 8.8
CVE-2024-35365

FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio …

Patch available
Fix from $1,950 2025-01-03
Ffmpeg MEDIUM 6.2
CVE-2024-36613

FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-o…

Patch available
Fix from $1,600 2025-01-03
Ffmpeg HIGH 7.5
CVE-2023-6603

A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers…

Fix: after 6.0
Fix from $1,950 2024-12-31
Ffmpeg MEDIUM 5.3
CVE-2023-6602

A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files …

Fix: after 6.0
Fix from $1,600 2024-12-31
Ffmpeg CRITICAL 9.8
CVE-2024-35368

FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.

Patch available
Fix from $2,300 2024-11-29
Ffmpeg CRITICAL 9.1
CVE-2024-35366

FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing cer…

Patch available
Fix from $2,300 2024-11-29
Ffmpeg CRITICAL 9.1
CVE-2024-35367

FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer

Patch available
Fix from $2,300 2024-11-29
Ffmpeg MEDIUM 6.5
CVE-2024-36616

An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application vi…

Patch available
Fix from $1,600 2024-11-29
Ffmpeg MEDIUM 5.9
CVE-2024-36615

FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, a…

Patch available
Fix from $1,600 2024-11-29
Ffmpeg MEDIUM 6.2
CVE-2024-36617

FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.

Fix: 3.4.14 / 4.2.9+
Fix from $1,600 2024-11-29
Ffmpeg MEDIUM 6.2
CVE-2024-36618

FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a deni…

Patch available
Fix from $1,600 2024-11-29
Ffmpeg MEDIUM 5.5
CVE-2024-35369

In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation…

Patch available
Fix from $1,600 2024-11-29
Ffmpeg MEDIUM 5.3
CVE-2024-36619

FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block ty…

Patch available
Fix from $1,600 2024-11-29
Ffmpeg HIGH 8.8
CVE-2024-7272

A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audiodata of the file /libswresamp…

Fix: 5.1.6+
Fix from $1,950 2024-08-12
Ffmpeg HIGH 8.8
CVE-2024-7055

A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libav…

Fix: 4.3.8 / 4.4.5+
Fix from $1,950 2024-08-06
Ffmpeg HIGH 8.4
CVE-2024-32229

FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.

No fix yet
Fix from $1,950 2024-07-01
Ffmpeg HIGH 7.8
CVE-2024-32230

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg…

No fix yet
Fix from $1,950 2024-07-01
Ffmpeg MEDIUM 6.6
CVE-2024-32228

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

Patch available
Fix from $1,600 2024-07-01
Ffmpeg HIGH 7.8
CVE-2023-51794

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:…

Mitigation only
Fix from $1,950 2024-04-26
Ffmpeg HIGH 7.8
CVE-2023-51793

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in…

Mitigation only
Fix from $1,950 2024-04-19
Ffmpeg HIGH 7.5
CVE-2024-22861

Integer overflow vulnerability in FFmpeg before n6.1, allows attackers to cause a denial of service (DoS) via the avcodec/osq module.

Patch available
Fix from $1,950 2024-01-27
Ffmpeg CRITICAL 9.8
CVE-2024-22860

Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the jpegxl_anim_read_packet component in …

Patch available
Fix from $2,300 2024-01-27
Ffmpeg CRITICAL 9.8
CVE-2024-22862

Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.

Patch available
Fix from $2,300 2024-01-27
Ffmpeg HIGH 7.8
CVE-2023-47470

Buffer Overflow vulnerability in Ffmpeg before github commit 4565747056a11356210ed8edcecb920105e40b60 allows a remote attacker to achieve an out-of-a…

Patch available
Fix from $1,950 2023-11-16
Ffmpeg MEDIUM 5.5
CVE-2023-46407

FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function.

Patch available
Fix from $1,600 2023-10-27
Ffmpeg MEDIUM 5.5
CVE-2021-28429

Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial o…

Patch available
Fix from $1,600 2023-08-11
Ffmpeg HIGH 7.5
CVE-2020-36138

An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).

Patch available
Fix from $1,950 2023-08-11
Ffmpeg HIGH 8.1
CVE-2022-48434

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows atta…

Fix: 5.1.2+
Fix from $1,950 2023-03-29