FFmpeg是FFmpeg组织开源的一套可录制、转换以及流化音视频的完整解决方案。 FFmpeg 3.4版本至8.1.2版本存在缓冲区错误漏洞,该漏洞源于vf_floodfill视频过滤器中的越界写入,当提供动态大小的视频流且禁用过滤器图重新初始化时,可能导致堆损坏和进程崩溃,严重时可执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65703 | 7.8 HIGH | FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder |
| CVE-2026-65706 | 7.8 HIGH | FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing |
| CVE-2026-65704 | 7.8 HIGH | FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder |
No comments yet