FFmpeg records
503 published records for vendor ffmpeg.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 53
- With a fix record
- 77.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer128
- CWE-20 Improper Input Validation39
- CWE-189 Numeric Errors33
- CWE-125 Out-of-bounds Read30
- CWE-787 Out-of-bounds Write29
- CWE-190 Integer Overflow or Wraparound23
The weakness classes this vendor ships most often: where to look.
CWEAll records
503 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2009-4637Proof of concept | FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that triggerffmpeg · ffmpeg · CWE-119 | Critical10.0 | — | 17.4% | Feb 9, 2010 |
42Plan | CVE-2016-10190Proof of concept | Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allffmpeg · ffmpeg · CWE-119 | Critical9.8 | — | 8.4% | Feb 9, 2017 |
42Plan | CVE-2009-4633No exploit | vorbis_dec.c in FFmpeg 0.5 uses an assignment operator when a comparison operator was intended, which might allow remote attackers to cause ffmpeg · ffmpeg · CWE-189 | Critical10.0 | — | 7.9% | Feb 9, 2010 |
42Plan | CVE-2009-4634No exploit | Multiple integer underflows in FFmpeg 0.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafffmpeg · ffmpeg · CWE-189 | Critical10.0 | — | 7.2% | Feb 9, 2010 |
41Plan | CVE-2016-10191Proof of concept | Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 ffmpeg · ffmpeg · CWE-119 | Critical9.8 | — | 7.5% | Feb 9, 2017 |
41Plan | CVE-2016-10192No exploit | Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remoffmpeg · ffmpeg · CWE-119 | Critical9.8 | — | 6.2% | Feb 9, 2017 |
41Plan | CVE-2008-4866No exploit | Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to havffmpeg · ffmpeg · CWE-119 | Critical10.0 | — | 4.7% | Oct 31, 2008 |
41Plan | CVE-2012-2786No exploit | Unspecified vulnerability in the decode_wdlt function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x befolibav · libav | Critical10.0 | — | 3.7% | Sep 10, 2012 |
41Plan | CVE-2012-2777No exploit | Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x blibav · libav | Critical10.0 | — | 3.3% | Sep 10, 2012 |
41Plan | CVE-2012-2803No exploit | Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0libav · libav · CWE-399 | Critical10.0 | — | 3.3% | Sep 10, 2012 |
41Plan | CVE-2012-2793No exploit | Unspecified vulnerability in the lag_decode_zero_run_line function in libavcodec/lagarith.c in FFmpeg before 0.11, and Libav 0.7.x before 0.libav · libav | Critical10.0 | — | 3.3% | Sep 10, 2012 |
41Plan | CVE-2012-2775No exploit | Unspecified vulnerability in the read_var_block_data function in libavcodec/alsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 andlibav · libav | Critical10.0 | — | 3.2% | Sep 10, 2012 |
41Plan | CVE-2012-2784No exploit | Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x blibav · libav | Critical10.0 | — | 3.2% | Sep 10, 2012 |
41Plan | CVE-2012-2790No exploit | Unspecified vulnerability in the read_var_block_data function in libavcodec/alsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 andlibav · libav | Critical10.0 | — | 3.2% | Sep 10, 2012 |
41Plan | CVE-2012-2779No exploit | Unspecified vulnerability in the decode_frame function in libavcodec/indeo5.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x libav · libav | Critical10.0 | — | 3.2% | Sep 10, 2012 |
41Plan | CVE-2012-2789No exploit | Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.libav · libav | Critical10.0 | — | 3.2% | Sep 10, 2012 |
41Plan | CVE-2012-2794No exploit | Unspecified vulnerability in the decode_mb_info function in libavcodec/indeo5.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.libav · libav | Critical10.0 | — | 3.2% | Sep 10, 2012 |
41Plan | CVE-2012-2783No exploit | Unspecified vulnerability in libavcodec/vp56.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impacffmpeg · ffmpeg | Critical10.0 | — | 3.2% | Sep 10, 2012 |
41Plan | CVE-2012-2788No exploit | Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.libav · libav | Critical10.0 | — | 3.2% | Sep 10, 2012 |
41Plan | CVE-2012-2796No exploit | Unspecified vulnerability in the vc1_decode_frame function in libavcodec/vc1dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unkffmpeg · ffmpeg | Critical10.0 | — | 3.2% | Sep 10, 2012 |
41Plan | CVE-2012-2791No exploit | Multiple unspecified vulnerabilities in the (1) decode_band_hdr function in indeo4.c and (2) ff_ivi_decode_blocks function in ivi_common.c iffmpeg · ffmpeg | Critical10.0 | — | 3.1% | Sep 10, 2012 |
41Plan | CVE-2012-2776No exploit | Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unklibav · libav | Critical10.0 | — | 3.1% | Sep 10, 2012 |
41Plan | CVE-2012-2787No exploit | Unspecified vulnerability in the decode_frame function in libavcodec/indeo4.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknownlibav · libav | Critical10.0 | — | 3.1% | Sep 10, 2012 |
41Plan | CVE-2012-2804No exploit | Unspecified vulnerability in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors, rlibav · libav | Critical10.0 | — | 3.1% | Sep 10, 2012 |
41Plan | CVE-2012-2801No exploit | Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impactlibav · libav | Critical10.0 | — | 3.0% | Sep 10, 2012 |
- CVE-2009-463745Plan
FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger
CriticalCVSS 10.0Proof of conceptEPSS 17%ffmpeg · ffmpegFeb 9, 2010
- CVE-2016-1019042Plan
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 all
CriticalCVSS 9.8Proof of conceptEPSS 8%ffmpeg · ffmpegFeb 9, 2017
- CVE-2009-463342Plan
vorbis_dec.c in FFmpeg 0.5 uses an assignment operator when a comparison operator was intended, which might allow remote attackers to cause
CriticalCVSS 10.0No exploitEPSS 8%ffmpeg · ffmpegFeb 9, 2010
- CVE-2009-463442Plan
Multiple integer underflows in FFmpeg 0.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a craf
CriticalCVSS 10.0No exploitEPSS 7%ffmpeg · ffmpegFeb 9, 2010
- CVE-2016-1019141Plan
Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2
CriticalCVSS 9.8Proof of conceptEPSS 7%ffmpeg · ffmpegFeb 9, 2017
- CVE-2016-1019241Plan
Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remo
CriticalCVSS 9.8No exploitEPSS 6%ffmpeg · ffmpegFeb 9, 2017
- CVE-2008-486641Plan
Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to hav
CriticalCVSS 10.0No exploitEPSS 5%ffmpeg · ffmpegOct 31, 2008
- CVE-2012-278641Plan
Unspecified vulnerability in the decode_wdlt function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x befo
CriticalCVSS 10.0No exploitEPSS 4%libav · libavSep 10, 2012
- CVE-2012-277741Plan
Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x b
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-280341Plan
Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-279341Plan
Unspecified vulnerability in the lag_decode_zero_run_line function in libavcodec/lagarith.c in FFmpeg before 0.11, and Libav 0.7.x before 0.
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-277541Plan
Unspecified vulnerability in the read_var_block_data function in libavcodec/alsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-278441Plan
Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x b
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-279041Plan
Unspecified vulnerability in the read_var_block_data function in libavcodec/alsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-277941Plan
Unspecified vulnerability in the decode_frame function in libavcodec/indeo5.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-278941Plan
Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-279441Plan
Unspecified vulnerability in the decode_mb_info function in libavcodec/indeo5.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-278341Plan
Unspecified vulnerability in libavcodec/vp56.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impac
CriticalCVSS 10.0No exploitEPSS 3%ffmpeg · ffmpegSep 10, 2012
- CVE-2012-278841Plan
Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-279641Plan
Unspecified vulnerability in the vc1_decode_frame function in libavcodec/vc1dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unk
CriticalCVSS 10.0No exploitEPSS 3%ffmpeg · ffmpegSep 10, 2012
- CVE-2012-279141Plan
Multiple unspecified vulnerabilities in the (1) decode_band_hdr function in indeo4.c and (2) ff_ivi_decode_blocks function in ivi_common.c i
CriticalCVSS 10.0No exploitEPSS 3%ffmpeg · ffmpegSep 10, 2012
- CVE-2012-277641Plan
Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unk
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-278741Plan
Unspecified vulnerability in the decode_frame function in libavcodec/indeo4.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-280441Plan
Unspecified vulnerability in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors, r
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012
- CVE-2012-280141Plan
Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact
CriticalCVSS 10.0No exploitEPSS 3%libav · libavSep 10, 2012