<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – FFmpeg</title>
  <link>https://cvedaily.com/pages/tags/ffmpeg.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ffmpeg.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – FFmpeg</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-40962 – FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40962</guid>
    <pubDate>Thu, 16 Apr 2026 02:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40962</strong></p>
  <p>FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6385 – A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6385</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6385</strong></p>
  <p>A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35033 – Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35033</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35033</strong></p>
  <p>Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOptions method in StreamingHelpers.cs adds any lowercase query parameter to a dictionary without validation, bypassing the RegularExpression attribute on…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30999 – A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30999</guid>
    <pubDate>Mon, 13 Apr 2026 15:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30999</strong></p>
  <p>A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30998 – An improper resource deallocation and closure vulnerability in the tools/zmqsend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30998</guid>
    <pubDate>Mon, 13 Apr 2026 15:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30998</strong></p>
  <p>An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30997 – An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30997</guid>
    <pubDate>Mon, 13 Apr 2026 15:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30997</strong></p>
  <p>An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35450 – WWBN AVideo is an open source video platform. In versions 26.0 and prior, the pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35450</guid>
    <pubDate>Mon, 06 Apr 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35450</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without any authentication. All sibling FFmpeg management endpoints (kill.ffmpeg.json.php, list.ffmpeg.json.php, ffmpeg.php) require User::isAdmin().</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33482 – WWBN AVideo is an open source video platform. In versions up to and including 26...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33482</guid>
    <pubDate>Mon, 23 Mar 2026 15:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33482</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/functions.php` is designed to prevent OS command injection in ffmpeg commands by stripping dangerous shell metacharacters (`&&`, `;`, `|`, `` ` ``, `<`, `>`). However, it fails to strip `$()` (bash command substitution syntax). Since the sanitized co…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33024 – AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33024</guid>
    <pubDate>Fri, 20 Mar 2026 05:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33024</strong></p>
  <p>AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpoints getImage.php and getImageMP4.php. Both endpoints accept a base64Url GET parameter, base64-decode it, and pass the resulting URL to ffmpeg as an input source without any authentication requirement. The prior validation only checked that the URL w…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-69693 – Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69693</guid>
    <pubDate>Mon, 16 Mar 2026 20:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-69693</strong></p>
  <p>Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in ou…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3682 – A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3682</guid>
    <pubDate>Sun, 08 Mar 2026 00:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3682</strong></p>
  <p>A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. This vulnerability affects the function Execute of the file /internal/service/ffmpeg/ffmpeg.go. The manipulation leads to argument injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-12343 – A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12343</guid>
    <pubDate>Wed, 18 Feb 2026 21:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-12343</strong></p>
  <p>A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-b…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10256 – A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10256</guid>
    <pubDate>Wed, 18 Feb 2026 21:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10256</strong></p>
  <p>A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash,…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22778 – vLLM is an inference and serving engine for large language models (LLMs). From 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22778</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22778</strong></p>
  <p>vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-71140 – In the Linux kernel, the following vulnerability has been resolved:

media: medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-71140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-71140</guid>
    <pubDate>Wed, 14 Jan 2026 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-71140</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: mediatek: vcodec: Use spinlock for context list protection lock  Previously a mutex was added to protect the encoder and decoder context lists from unexpected changes originating from the SCP IP block, causing the context pointer to go invalid, resulting in a NULL pointer dereference in the IPI handler.  Turns out on the…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-71140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-50790 – SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50790</guid>
    <pubDate>Tue, 30 Dec 2025 23:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-50790</strong></p>
  <p>SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream details without requiring authentication.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25139 – FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25139</guid>
    <pubDate>Wed, 24 Dec 2025 20:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25139</strong></p>
  <p>FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-53981 – PhotoShow 3.0 contains a remote code execution vulnerability that allows authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53981</guid>
    <pubDate>Mon, 22 Dec 2025 22:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-53981</strong></p>
  <p>PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload process.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63757 – Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswsca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63757</guid>
    <pubDate>Thu, 18 Dec 2025 15:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63757</strong></p>
  <p>Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-58286 – dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-58286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-58286</guid>
    <pubDate>Thu, 11 Dec 2025 22:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-58286</strong></p>
  <p>dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-58286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7700 – A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7700</guid>
    <pubDate>Fri, 07 Nov 2025 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7700</strong></p>
  <p>A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9951 – A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9951</guid>
    <pubDate>Tue, 09 Sep 2025 14:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9951</strong></p>
  <p>A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57616 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57616</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57616</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleaved method allows an attacker to cause a denial of service or memory corruption. The method violates Rust's aliasing rules by modifying a data structure through a mutable pointer while only holding an immutable reference, which can lead to undefined behavior when the data is acce…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57615 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57615</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57615</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new constructor function allows an attacker to cause a denial of service via a null pointer dereference. The vulnerability stems from an unchecked cast of a usize parameter to c_int, which can result in a negative value being passed to the underlying C function sws_allocVec().</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57614 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57614</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57614</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in the cached method allows an attacker to cause a denial of service or potentially execute arbitrary code. The vulnerability occurs when dimension parameters are zero or exceed i32::MAX, leading to an unchecked cast that violates the underlying C function's preconditions and trigge…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57613 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57613</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57613</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input() constructor function allows an attacker to cause a denial of service. The vulnerability is triggered when the avio_alloc_context() call fails and returns NULL, which is then stored and later dereferenced by the Io struct's Drop implementation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57612 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57612</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57612</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name() method allows an attacker to cause a denial of service. The vulnerability exists because the method fails to check for a NULL return value from the av_get_sample_fmt_name() C function, which can be triggered by providing an unrecognized sample format.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57611 – An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57611</guid>
    <pubDate>Tue, 02 Sep 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57611</strong></p>
  <p>An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the dump() method allows an attacker to cause a denial of service. The vulnerability exists because the method fails to check the return value of avfilter_graph_dump() for NULL, leading to a crash if the underlying memory allocation fails.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55634 – Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55634</guid>
    <pubDate>Fri, 22 Aug 2025 17:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55634</strong></p>
  <p>Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to cause a Denial of Service (DoS) via initiating a large number of simultaneous ffmpeg-based stream pushes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55069 – ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_heade...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55069</guid>
    <pubDate>Fri, 02 May 2025 22:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55069</strong></p>
  <p>ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31499 – Jellyfin is an open source self hosted media server. Versions before 10.10.7 are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31499</guid>
    <pubDate>Tue, 15 Apr 2025 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31499</strong></p>
  <p>Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to possibly achieve remote code execution by anyone with credentials to a low-privileged user. This vulnerability was previously reported in CVE-2023-49096 and patched in version 10.8.13, but the patch can be bypassed. The original fix sanitizes some p…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-1816 – A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1816</guid>
    <pubDate>Sun, 02 Mar 2025 14:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1816</strong></p>
  <p>A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This affects the function audio_element_obu of the file libavformat/iamf_parse.c of the component IAMF File Handler. The manipulation of the argument num_parameters leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-1594 – A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1594</guid>
    <pubDate>Sun, 23 Feb 2025 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1594</strong></p>
  <p>A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25473 – FFmpeg git master before commit c08d30 was discovered to contain a memory leak i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25473</guid>
    <pubDate>Tue, 18 Feb 2025 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25473</strong></p>
  <p>FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25471 – FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25471</guid>
    <pubDate>Tue, 18 Feb 2025 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25471</strong></p>
  <p>FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22920 – A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22920</guid>
    <pubDate>Tue, 18 Feb 2025 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22920</strong></p>
  <p>A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22919 – A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22919</guid>
    <pubDate>Tue, 18 Feb 2025 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22919</strong></p>
  <p>A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25469 – FFmpeg git-master before commit d5873b was discovered to contain a memory leak i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25469</guid>
    <pubDate>Tue, 18 Feb 2025 22:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25469</strong></p>
  <p>FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25468 – FFmpeg git-master before commit d5873b was discovered to contain a memory leak i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25468</guid>
    <pubDate>Tue, 18 Feb 2025 22:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25468</strong></p>
  <p>FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22921 – FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22921</guid>
    <pubDate>Tue, 18 Feb 2025 22:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22921</strong></p>
  <p>FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-1373 – A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1373</guid>
    <pubDate>Mon, 17 Feb 2025 04:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-1373</strong></p>
  <p>A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function mov_read_trak of the file libavformat/mov.c of the component MOV Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The patch is identified as 43be8d07281caca…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25286 – Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25286</guid>
    <pubDate>Thu, 13 Feb 2025 01:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25286</strong></p>
  <p>Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution may be possible in web-accessible installations of Homarus in certain configurations. The issue has been patched in `islandora/crayfish:4.1.0`. Some workarounds are available. The exploit requires making a request against the Homar…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-150</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-56515 – Matrix Media Repo (MMR) is a highly configurable multi-homeserver media reposito...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56515</guid>
    <pubDate>Thu, 16 Jan 2025 20:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-56515</strong></p>
  <p>Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnailers are enabled (they are disabled by default), a user may upload a file which claims to be either of these types and request a thumbnail to invoke a different decoder in ImageMagick. In some ImageMagick installations, this includes the capability to run Ghostscript to decode t…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0518 – Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0518</guid>
    <pubDate>Thu, 16 Jan 2025 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0518</strong></p>
  <p>Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .  This issue affects FFmpeg: 7.1.  Issue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a   https://github.com/FFm…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6605 – A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6605</guid>
    <pubDate>Mon, 06 Jan 2025 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6605</strong></p>
  <p>A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6604 – A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6604</guid>
    <pubDate>Mon, 06 Jan 2025 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6604</strong></p>
  <p>A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6601 – A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6601</guid>
    <pubDate>Mon, 06 Jan 2025 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6601</strong></p>
  <p>A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36613 – FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36613</guid>
    <pubDate>Fri, 03 Jan 2025 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36613</strong></p>
  <p>FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35365 – FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35365</guid>
    <pubDate>Fri, 03 Jan 2025 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35365</strong></p>
  <p>FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6603 – A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6603</guid>
    <pubDate>Tue, 31 Dec 2024 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6603</strong></p>
  <p>A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6602 – A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6602</guid>
    <pubDate>Tue, 31 Dec 2024 15:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6602</strong></p>
  <p>A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-35368 – FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35368</guid>
    <pubDate>Fri, 29 Nov 2024 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-35368</strong></p>
  <p>FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-35367 – FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, sta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35367</guid>
    <pubDate>Fri, 29 Nov 2024 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-35367</strong></p>
  <p>FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-35366 – FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35366</guid>
    <pubDate>Fri, 29 Nov 2024 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-35366</strong></p>
  <p>FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36616 – An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36616</guid>
    <pubDate>Fri, 29 Nov 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36616</strong></p>
  <p>An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36615 – FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could le...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36615</guid>
    <pubDate>Fri, 29 Nov 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36615</strong></p>
  <p>FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36618 – FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36618</guid>
    <pubDate>Fri, 29 Nov 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36618</strong></p>
  <p>FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36617 – FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36617</guid>
    <pubDate>Fri, 29 Nov 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36617</strong></p>
  <p>FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36619 – FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec librar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36619</guid>
    <pubDate>Fri, 29 Nov 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36619</strong></p>
  <p>FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35369 – In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35369</guid>
    <pubDate>Fri, 29 Nov 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35369</strong></p>
  <p>In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7272 – A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7272</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7272</strong></p>
  <p>A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audiodata of the file /libswresample/swresample.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. This issue was fixed in version 6.0 by 9903ba28c28ab18dc7b7b6fb8571cc8b5caae1a6 but a backport for 5.1 was forgotten. The exploit h…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7055 – A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as criti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7055</guid>
    <pubDate>Tue, 06 Aug 2024 06:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7055</strong></p>
  <p>A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to address this issue. It is recomm…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32230 – FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32230</guid>
    <pubDate>Mon, 01 Jul 2024 21:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32230</strong></p>
  <p>FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32229 – FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32229</guid>
    <pubDate>Mon, 01 Jul 2024 21:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32229</strong></p>
  <p>FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32228 – FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32228</guid>
    <pubDate>Mon, 01 Jul 2024 21:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32228</strong></p>
  <p>FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51794 – Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51794</guid>
    <pubDate>Fri, 26 Apr 2024 15:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51794</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51798 – Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51798</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51798</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-51797 – Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51797</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-51797</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-51796 – Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51796</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-51796</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame.</p>
  <p><strong>CVSS:</strong> 3.6 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51795 – Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51795</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51795</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51793 – Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51793</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51793</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51791 – Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51791</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51791</strong></p>
  <p>Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50010 – FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50010</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50010</strong></p>
  <p>FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50009 – FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gauss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50009</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50009</strong></p>
  <p>FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50008 – FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50008</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50008</strong></p>
  <p>FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-50007 – FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50007</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-50007</strong></p>
  <p>FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49502 – Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49502</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49502</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49501 – Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49501</guid>
    <pubDate>Fri, 19 Apr 2024 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49501</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-31585 – FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31585</guid>
    <pubDate>Wed, 17 Apr 2024 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-31585</strong></p>
  <p>FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31582 – FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31582</guid>
    <pubDate>Wed, 17 Apr 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31582</strong></p>
  <p>FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-31581 – FFmpeg version n6.1 was discovered to contain an improper validation of array in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31581</guid>
    <pubDate>Wed, 17 Apr 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-31581</strong></p>
  <p>FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within the application.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31578 – FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31578</guid>
    <pubDate>Wed, 17 Apr 2024 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31578</strong></p>
  <p>FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49528 – Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a loc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49528</guid>
    <pubDate>Fri, 12 Apr 2024 06:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49528</strong></p>
  <p>Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-2029 – A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2029</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-2029</strong></p>
  <p>A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for converting audio files to WAV format for transcription. The vulnerability arises due to the lack of sanitization of user-supplied filenames before passing them to ffmpeg via a shell command, allowing an attacker to execute arbitrary commands on the host sy…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22861 – Integer overflow vulnerability in FFmpeg before n6.1, allows attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22861</guid>
    <pubDate>Sat, 27 Jan 2024 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22861</strong></p>
  <p>Integer overflow vulnerability in FFmpeg before n6.1, allows attackers to cause a denial of service (DoS) via the avcodec/osq module.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22862 – Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22862</guid>
    <pubDate>Sat, 27 Jan 2024 06:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22862</strong></p>
  <p>Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22860 – Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22860</guid>
    <pubDate>Sat, 27 Jan 2024 06:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22860</strong></p>
  <p>Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the jpegxl_anim_read_packet component in the JPEG XL Animation decoder.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-48909 – An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48909</guid>
    <pubDate>Fri, 12 Jan 2024 09:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-48909</strong></p>
  <p>An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49096 – Jellyfin is a Free Software Media System for managing and streaming media. In af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49096</guid>
    <pubDate>Wed, 06 Dec 2023 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49096</strong></p>
  <p>Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosController, specifically the `/Videos/<itemId>/stream` and `/Videos/<itemId>/stream.<container>` endpoints which are present in the current Jellyfin version. Additional endpoints in the AudioController might also be vulnerable, as they differ only slightly in…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47470 – Buffer Overflow vulnerability in Ffmpeg before github commit 4565747056a11356210...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47470</guid>
    <pubDate>Thu, 16 Nov 2023 03:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47470</strong></p>
  <p>Buffer Overflow vulnerability in Ffmpeg before github commit 4565747056a11356210ed8edcecb920105e40b60 allows a remote attacker to achieve an out-of-array write, execute arbitrary code, and cause a denial of service (DoS) via the ref_pic_list_struct function in libavcodec/evc_ps.c</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46407 – FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46407</guid>
    <pubDate>Fri, 27 Oct 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46407</strong></p>
  <p>FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-28429 – Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28429</guid>
    <pubDate>Fri, 11 Aug 2023 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-28429</strong></p>
  <p>Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial of service (DoS) via crafted .mov file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36138 – An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36138</guid>
    <pubDate>Fri, 11 Aug 2023 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36138</strong></p>
  <p>An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4907 – Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4907</guid>
    <pubDate>Sat, 29 Jul 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4907</strong></p>
  <p>Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-39018 – FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39018</guid>
    <pubDate>Fri, 28 Jul 2023 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-39018</strong></p>
  <p>FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no realistic use cases in which FFmpeg.java uses untrusted input for the path of the executable file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48434 – libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other prod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48434</guid>
    <pubDate>Wed, 29 Mar 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48434</strong></p>
  <p>libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-3341 – A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_heade...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3341</guid>
    <pubDate>Thu, 12 Jan 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-3341</strong></p>
  <p>A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-3109 – An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3109</guid>
    <pubDate>Fri, 16 Dec 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-3109</strong></p>
  <p>An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-3965 – A vulnerability classified as problematic was found in ffmpeg. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3965</guid>
    <pubDate>Sun, 13 Nov 2022 08:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-3965</strong></p>
  <p>A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b36ed8edd. It is recommended to…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-3964 – A vulnerability classified as problematic has been found in ffmpeg. This affects...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3964</guid>
    <pubDate>Sun, 13 Nov 2022 08:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-3964</strong></p>
  <p>A vulnerability classified as problematic has been found in ffmpeg. This affects an unknown part of the file libavcodec/rpzaenc.c of the component QuickTime RPZA Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. It is possible to initiate the attack remotely. The name of the patch is 92f9b28ed84a77138105475beba16c146bdaf984. It is recommended to apply a patch to…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3964">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
