<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – FFmpeg (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ffmpeg.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ffmpeg-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – FFmpeg (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-35033 – Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35033</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35033</strong></p>
  <p>Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOptions method in StreamingHelpers.cs adds any lowercase query parameter to a dictionary without validation, bypassing the RegularExpression attribute on…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30999 – A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30999</guid>
    <pubDate>Mon, 13 Apr 2026 15:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30999</strong></p>
  <p>A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30998 – An improper resource deallocation and closure vulnerability in the tools/zmqsend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30998</guid>
    <pubDate>Mon, 13 Apr 2026 15:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30998</strong></p>
  <p>An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30997 – An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30997</guid>
    <pubDate>Mon, 13 Apr 2026 15:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30997</strong></p>
  <p>An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33482 – WWBN AVideo is an open source video platform. In versions up to and including 26...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33482</guid>
    <pubDate>Mon, 23 Mar 2026 15:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33482</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/functions.php` is designed to prevent OS command injection in ffmpeg commands by stripping dangerous shell metacharacters (`&&`, `;`, `|`, `` ` ``, `<`, `>`). However, it fails to strip `$()` (bash command substitution syntax). Since the sanitized co…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33024 – AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33024</guid>
    <pubDate>Fri, 20 Mar 2026 05:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33024</strong></p>
  <p>AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpoints getImage.php and getImageMP4.php. Both endpoints accept a base64Url GET parameter, base64-decode it, and pass the resulting URL to ffmpeg as an input source without any authentication requirement. The prior validation only checked that the URL w…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22778 – vLLM is an inference and serving engine for large language models (LLMs). From 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22778</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22778</strong></p>
  <p>vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-50790 – SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50790</guid>
    <pubDate>Tue, 30 Dec 2025 23:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-50790</strong></p>
  <p>SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream details without requiring authentication.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25139 – FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25139</guid>
    <pubDate>Wed, 24 Dec 2025 20:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25139</strong></p>
  <p>FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-53981 – PhotoShow 3.0 contains a remote code execution vulnerability that allows authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53981</guid>
    <pubDate>Mon, 22 Dec 2025 22:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-53981</strong></p>
  <p>PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload process.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63757 – Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswsca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63757</guid>
    <pubDate>Thu, 18 Dec 2025 15:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63757</strong></p>
  <p>Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-58286 – dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-58286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-58286</guid>
    <pubDate>Thu, 11 Dec 2025 22:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-58286</strong></p>
  <p>dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-58286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9951 – A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9951</guid>
    <pubDate>Tue, 09 Sep 2025 14:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9951</strong></p>
  <p>A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57616 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57616</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57616</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleaved method allows an attacker to cause a denial of service or memory corruption. The method violates Rust's aliasing rules by modifying a data structure through a mutable pointer while only holding an immutable reference, which can lead to undefined behavior when the data is acce…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57615 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57615</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57615</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new constructor function allows an attacker to cause a denial of service via a null pointer dereference. The vulnerability stems from an unchecked cast of a usize parameter to c_int, which can result in a negative value being passed to the underlying C function sws_allocVec().</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57614 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57614</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57614</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in the cached method allows an attacker to cause a denial of service or potentially execute arbitrary code. The vulnerability occurs when dimension parameters are zero or exceed i32::MAX, leading to an unchecked cast that violates the underlying C function's preconditions and trigge…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57613 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57613</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57613</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input() constructor function allows an attacker to cause a denial of service. The vulnerability is triggered when the avio_alloc_context() call fails and returns NULL, which is then stored and later dereferenced by the Io struct's Drop implementation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57612 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57612</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57612</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name() method allows an attacker to cause a denial of service. The vulnerability exists because the method fails to check for a NULL return value from the av_get_sample_fmt_name() C function, which can be triggered by providing an unrecognized sample format.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55634 – Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55634</guid>
    <pubDate>Fri, 22 Aug 2025 17:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55634</strong></p>
  <p>Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to cause a Denial of Service (DoS) via initiating a large number of simultaneous ffmpeg-based stream pushes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31499 – Jellyfin is an open source self hosted media server. Versions before 10.10.7 are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31499</guid>
    <pubDate>Tue, 15 Apr 2025 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31499</strong></p>
  <p>Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to possibly achieve remote code execution by anyone with credentials to a low-privileged user. This vulnerability was previously reported in CVE-2023-49096 and patched in version 10.8.13, but the patch can be bypassed. The original fix sanitizes some p…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25286 – Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25286</guid>
    <pubDate>Thu, 13 Feb 2025 01:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25286</strong></p>
  <p>Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution may be possible in web-accessible installations of Homarus in certain configurations. The issue has been patched in `islandora/crayfish:4.1.0`. Some workarounds are available. The exploit requires making a request against the Homar…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-150</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6605 – A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6605</guid>
    <pubDate>Mon, 06 Jan 2025 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6605</strong></p>
  <p>A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35365 – FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35365</guid>
    <pubDate>Fri, 03 Jan 2025 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35365</strong></p>
  <p>FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6603 – A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6603</guid>
    <pubDate>Tue, 31 Dec 2024 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6603</strong></p>
  <p>A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-35368 – FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35368</guid>
    <pubDate>Fri, 29 Nov 2024 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-35368</strong></p>
  <p>FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-35367 – FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, sta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35367</guid>
    <pubDate>Fri, 29 Nov 2024 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-35367</strong></p>
  <p>FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-35366 – FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35366</guid>
    <pubDate>Fri, 29 Nov 2024 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-35366</strong></p>
  <p>FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32230 – FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32230</guid>
    <pubDate>Mon, 01 Jul 2024 21:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32230</strong></p>
  <p>FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32229 – FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32229</guid>
    <pubDate>Mon, 01 Jul 2024 21:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32229</strong></p>
  <p>FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51794 – Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51794</guid>
    <pubDate>Fri, 26 Apr 2024 15:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51794</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51798 – Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51798</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51798</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51795 – Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51795</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51795</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51793 – Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51793</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51793</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51791 – Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51791</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51791</strong></p>
  <p>Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50010 – FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50010</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50010</strong></p>
  <p>FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50009 – FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gauss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50009</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50009</strong></p>
  <p>FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50008 – FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50008</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50008</strong></p>
  <p>FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49502 – Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49502</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49502</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49501 – Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49501</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49501</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31582 – FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31582</guid>
    <pubDate>Wed, 17 Apr 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31582</strong></p>
  <p>FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-31581 – FFmpeg version n6.1 was discovered to contain an improper validation of array in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31581</guid>
    <pubDate>Wed, 17 Apr 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-31581</strong></p>
  <p>FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within the application.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31578 – FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31578</guid>
    <pubDate>Wed, 17 Apr 2024 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31578</strong></p>
  <p>FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49528 – Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a loc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49528</guid>
    <pubDate>Fri, 12 Apr 2024 06:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49528</strong></p>
  <p>Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-2029 – A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2029</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-2029</strong></p>
  <p>A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for converting audio files to WAV format for transcription. The vulnerability arises due to the lack of sanitization of user-supplied filenames before passing them to ffmpeg via a shell command, allowing an attacker to execute arbitrary commands on the host sy…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22861 – Integer overflow vulnerability in FFmpeg before n6.1, allows attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22861</guid>
    <pubDate>Sat, 27 Jan 2024 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22861</strong></p>
  <p>Integer overflow vulnerability in FFmpeg before n6.1, allows attackers to cause a denial of service (DoS) via the avcodec/osq module.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22862 – Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22862</guid>
    <pubDate>Sat, 27 Jan 2024 06:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22862</strong></p>
  <p>Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22860 – Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22860</guid>
    <pubDate>Sat, 27 Jan 2024 06:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22860</strong></p>
  <p>Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the jpegxl_anim_read_packet component in the JPEG XL Animation decoder.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-48909 – An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48909</guid>
    <pubDate>Fri, 12 Jan 2024 09:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-48909</strong></p>
  <p>An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49096 – Jellyfin is a Free Software Media System for managing and streaming media. In af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49096</guid>
    <pubDate>Wed, 06 Dec 2023 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49096</strong></p>
  <p>Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosController, specifically the `/Videos/<itemId>/stream` and `/Videos/<itemId>/stream.<container>` endpoints which are present in the current Jellyfin version. Additional endpoints in the AudioController might also be vulnerable, as they differ only slightly in…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47470 – Buffer Overflow vulnerability in Ffmpeg before github commit 4565747056a11356210...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47470</guid>
    <pubDate>Thu, 16 Nov 2023 03:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47470</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg before github commit 4565747056a11356210ed8edcecb920105e40b60 allows a remote attacker to achieve an out-of-array write, execute arbitrary code, and cause a denial of service (DoS) via the ref_pic_list_struct function in libavcodec/evc_ps.c</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36138 – An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36138</guid>
    <pubDate>Fri, 11 Aug 2023 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36138</strong></p>
  <p>An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4907 – Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4907</guid>
    <pubDate>Sat, 29 Jul 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4907</strong></p>
  <p>Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-39018 – FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39018</guid>
    <pubDate>Fri, 28 Jul 2023 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-39018</strong></p>
  <p>FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no realistic use cases in which FFmpeg.java uses untrusted input for the path of the executable file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48434 – libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other prod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48434</guid>
    <pubDate>Wed, 29 Mar 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48434</strong></p>
  <p>libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-3109 – An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3109</guid>
    <pubDate>Fri, 16 Dec 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-3109</strong></p>
  <p>An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-2566 – A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2566</guid>
    <pubDate>Fri, 23 Sep 2022 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-2566</strong></p>
  <p>A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc()`. An attacker can cause remote code execution via a malicious mp4 file. We recommend u…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-28435 – This affects all versions of package ffmpeg-sdk. The injection point is located ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28435</guid>
    <pubDate>Mon, 25 Jul 2022 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-28435</strong></p>
  <p>This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-125024 – A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-125024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-125024</guid>
    <pubDate>Sun, 19 Jun 2022 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-125024</strong></p>
  <p>A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function lag_decode_frame. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-125024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-125020 – A vulnerability has been found in FFmpeg 2.0 and classified as critical. This vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-125020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-125020</guid>
    <pubDate>Sun, 19 Jun 2022 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-125020</strong></p>
  <p>A vulnerability has been found in FFmpeg 2.0 and classified as critical. This vulnerability affects the function decode_update_thread_context. The manipulation leads to memory corruption. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-125020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-125017 – A vulnerability classified as critical was found in FFmpeg 2.0. This vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-125017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-125017</guid>
    <pubDate>Sat, 18 Jun 2022 07:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-125017</strong></p>
  <p>A vulnerability classified as critical was found in FFmpeg 2.0. This vulnerability affects the function rpza_decode_stream. The manipulation leads to memory corruption. The attack can be initiated remotely. The name of the patch is Fixes Invalid Writes. It is recommended to apply a patch to fix this issue.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-125017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-125015 – A vulnerability classified as critical has been found in FFmpeg 2.0. Affected is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-125015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-125015</guid>
    <pubDate>Sat, 18 Jun 2022 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-125015</strong></p>
  <p>A vulnerability classified as critical has been found in FFmpeg 2.0. Affected is the function read_var_block_data. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-125015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35504 – Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35504</guid>
    <pubDate>Tue, 05 Oct 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35504</strong></p>
  <p>Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38094 – Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38094</guid>
    <pubDate>Mon, 20 Sep 2021 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38094</strong></p>
  <p>Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38093 – Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38093</guid>
    <pubDate>Mon, 20 Sep 2021 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38093</strong></p>
  <p>Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38092 – Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_conv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38092</guid>
    <pubDate>Mon, 20 Sep 2021 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38092</strong></p>
  <p>Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38091 – Integer Overflow vulnerability in function filter16_sobel in libavfilter/vf_conv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38091</guid>
    <pubDate>Mon, 20 Sep 2021 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38091</strong></p>
  <p>Integer Overflow vulnerability in function filter16_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38090 – Integer Overflow vulnerability in function filter16_roberts in libavfilter/vf_co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38090</guid>
    <pubDate>Mon, 20 Sep 2021 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38090</strong></p>
  <p>Integer Overflow vulnerability in function filter16_roberts in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-20898 – Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-20898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-20898</guid>
    <pubDate>Mon, 20 Sep 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-20898</strong></p>
  <p>Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-20898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-20896 – An issue was discovered in function latm_write_packet in libavformat/latmenc.c i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-20896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-20896</guid>
    <pubDate>Mon, 20 Sep 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-20896</strong></p>
  <p>An issue was discovered in function latm_write_packet in libavformat/latmenc.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a Null pointer dereference.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-20896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-20892 – An issue was discovered in function filter_frame in libavfilter/vf_lenscorrectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-20892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-20892</guid>
    <pubDate>Mon, 20 Sep 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-20892</strong></p>
  <p>An issue was discovered in function filter_frame in libavfilter/vf_lenscorrection.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a division by zero.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-369</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-20892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-20891 – Buffer Overflow vulnerability in function config_input in libavfilter/vf_gblur.c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-20891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-20891</guid>
    <pubDate>Mon, 20 Sep 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-20891</strong></p>
  <p>Buffer Overflow vulnerability in function config_input in libavfilter/vf_gblur.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-20891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38171 – adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38171</guid>
    <pubDate>Sat, 21 Aug 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38171</strong></p>
  <p>adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38291 – FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers fro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38291</guid>
    <pubDate>Thu, 12 Aug 2021 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38291</strong></p>
  <p>FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-21688 – A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-21688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-21688</guid>
    <pubDate>Tue, 10 Aug 2021 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-21688</strong></p>
  <p>A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-21688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33815 – dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an out-of-bounds array a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33815</guid>
    <pubDate>Thu, 03 Jun 2021 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33815</strong></p>
  <p>dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an out-of-bounds array access because dc_count is not strictly checked.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22036 – A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22036</guid>
    <pubDate>Tue, 01 Jun 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22036</strong></p>
  <p>A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22035 – A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22035</guid>
    <pubDate>Tue, 01 Jun 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22035</strong></p>
  <p>A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22034 – A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22034</guid>
    <pubDate>Thu, 27 May 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22034</strong></p>
  <p>A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_floodfill.c, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22032 – A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22032</guid>
    <pubDate>Thu, 27 May 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22032</strong></p>
  <p>A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22027 – A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22027</guid>
    <pubDate>Thu, 27 May 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22027</strong></p>
  <p>A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighbor.c, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22023 – A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22023</guid>
    <pubDate>Thu, 27 May 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22023</strong></p>
  <p>A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_bitplanenoise.c, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22022 – A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22022</guid>
    <pubDate>Thu, 27 May 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22022</strong></p>
  <p>A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22017 – A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_recta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22017</guid>
    <pubDate>Thu, 27 May 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22017</strong></p>
  <p>A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/drawutils.c, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22016 – A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22016</guid>
    <pubDate>Thu, 27 May 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22016</strong></p>
  <p>A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.h when writing .mov files, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22031 – A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22031</guid>
    <pubDate>Thu, 27 May 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22031</strong></p>
  <p>A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_w3fdif.c in filter16_complex_low, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22030 – A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22030</guid>
    <pubDate>Thu, 27 May 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22030</strong></p>
  <p>A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/af_afade.c in crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22029 – A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22029</guid>
    <pubDate>Thu, 27 May 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22029</strong></p>
  <p>A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22015 – Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the ou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22015</guid>
    <pubDate>Wed, 26 May 2021 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22015</strong></p>
  <p>Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24020 – Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24020</guid>
    <pubDate>Wed, 26 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24020</strong></p>
  <p>Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavfilter/dnn/dnn_backend_native_layer_pad.c due to a call to memcpy without length checks, which could let a remote malicious user execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-20451 – Denial of Service issue in FFmpeg 4.2 due to resource management errors via ffto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-20451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-20451</guid>
    <pubDate>Tue, 25 May 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-20451</strong></p>
  <p>Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-20451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-20450 – FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavfo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-20450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-20450</guid>
    <pubDate>Tue, 25 May 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-20450</strong></p>
  <p>FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavformat/aviobuf.c, which could cause a Denial of Service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-20450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-21041 – Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-21041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-21041</guid>
    <pubDate>Mon, 24 May 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-21041</strong></p>
  <p>Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-21041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-30123 – FFmpeg &lt;=4.3 contains a buffer overflow vulnerability in libavcodec through a cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30123</guid>
    <pubDate>Wed, 07 Apr 2021 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-30123</strong></p>
  <p>FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24995 – Buffer overflow vulnerability in sniff_channel_order function in aacdec_template...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24995</guid>
    <pubDate>Tue, 30 Mar 2021 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24995</strong></p>
  <p>Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to execute arbitrary code (local).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35965 – decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write beca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35965</guid>
    <pubDate>Mon, 04 Jan 2021 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35965</strong></p>
  <p>decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14212 – FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavform...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14212</guid>
    <pubDate>Tue, 16 Jun 2020 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14212</strong></p>
  <p>FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12473 – MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12473</guid>
    <pubDate>Wed, 29 Apr 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12473</strong></p>
  <p>MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-12284 – cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12284</guid>
    <pubDate>Tue, 28 Apr 2020 06:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-12284</strong></p>
  <p>cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-4610 – Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-4610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-4610</guid>
    <pubDate>Tue, 14 Jan 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-4610</strong></p>
  <p>Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-4610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18214 – The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and me...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18214</guid>
    <pubDate>Sat, 19 Oct 2019 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18214</strong></p>
  <p>The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for serial execution.)</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18214">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
