FFmpeg是FFmpeg组织开源的一个多媒体处理框架。 FFmpeg 0.5版本至9.0之前版本存在安全漏洞,该漏洞源于libavcodec/dvbsub_parser.c中的DVB字幕解析器存在有符号整数溢出,攻击者可通过提供特制的WTV文件触发堆缓冲区溢出,导致边界检查保护表达式回绕至INT_MIN,绕过PARSE_BUF_SIZE比较并调用memcpy,造成越界堆写入,可能导致内存损坏或代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-70632 | 7.8 HIGH | FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing |
| CVE-2026-70630 | 5.5 MEDIUM | FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder |
| CVE-2026-70629 | 5.5 MEDIUM | FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder |
| CVE-2026-70631 | 5.5 MEDIUM | FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder |
No comments yet