Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FFMPEG — Vulnerabilities & Security Advisories 41

Browse all 41 CVE security advisories affecting FFMPEG. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FFMPEG serves as a fundamental multimedia framework for processing audio, video, and other digital content across countless applications and systems. Historically, it has been susceptible to remote code execution vulnerabilities through crafted media files, often due to buffer overflows in parsing components. Other common issues include denial-of-service conditions and memory corruption flaws. While no single major incident stands out, its widespread deployment means vulnerabilities in FFMPEG can impact numerous products and services. The 11 recorded CVEs reflect ongoing security challenges in handling untrusted media data, requiring careful input validation and sandboxing when processing files from untrusted sources.

Top products by FFMPEG: FFMPEG MPEG-DASH
CVE ID Title CVSS Severity Published
CVE-2026-75147 FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c — FFmpeg CWE-125 7.1 High 2026-08-19
CVE-2026-75146 FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c — FFmpeg CWE-125 8.1 High 2026-08-19
CVE-2026-75145 FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer — FFmpeg CWE-681 5.8 Medium 2026-08-19
CVE-2026-75144 FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer — FFmpeg CWE-122 7.8 High 2026-08-19
CVE-2026-75143 FFmpeg Heap Buffer Overflow via RIST Protocol Reader — FFmpeg CWE-122 9.8 Critical 2026-08-19
CVE-2026-75142 FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c — FFmpeg CWE-121 7.8 High 2026-08-19
CVE-2026-75141 FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing — FFmpeg CWE-122 7.8 High 2026-08-19
CVE-2026-70632 FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing — FFmpeg CWE-787 7.8 High 2026-08-06
CVE-2026-70631 FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder — FFmpeg CWE-908 5.5 Medium 2026-08-06
CVE-2026-70630 FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder — FFmpeg CWE-908 5.5 Medium 2026-08-06
CVE-2026-70629 FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder — FFmpeg CWE-908 5.5 Medium 2026-08-06
CVE-2026-70628 FFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV File — FFmpeg CWE-190 7.8 High 2026-08-06
CVE-2026-66041 FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter — FFmpeg CWE-787 8.8 High 2026-07-24
CVE-2026-66040 FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder — FFmpeg CWE-122 8.8 High 2026-07-24
CVE-2026-66039 FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File — FFmpeg CWE-190 8.8 High 2026-07-24
CVE-2026-66038 FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c — FFmpeg CWE-908 6.5 Medium 2026-07-24
CVE-2026-66037 FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu() — FFmpeg CWE-770 6.5 Medium 2026-07-24
CVE-2026-66036 FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter — FFmpeg CWE-122 8.8 High 2026-07-24
CVE-2026-65706 FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing — FFmpeg CWE-787 7.8 High 2026-07-23
CVE-2026-65705 FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame() — FFmpeg CWE-787 7.8 High 2026-07-23
CVE-2026-65704 FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder — FFmpeg CWE-787 7.8 High 2026-07-23
CVE-2026-65703 FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder — FFmpeg CWE-787 7.8 High 2026-07-23
CVE-2026-64835 FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder — FFmpeg CWE-787 8.8 High 2026-07-22
CVE-2026-64834 FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer — FFmpeg CWE-835 7.5 High 2026-07-22
CVE-2026-64833 FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c — FFmpeg CWE-125 7.1 High 2026-07-22
CVE-2026-64832 FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c — FFmpeg CWE-415 8.8 High 2026-07-22
CVE-2026-64831 FFmpeg 8.0 - 8.1.2 Stack Buffer Overflow in Vulkan HEVC Decoder — FFmpeg CWE-121 8.8 High 2026-07-22
CVE-2026-64830 FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer — FFmpeg CWE-122 8.8 High 2026-07-22
CVE-2026-58049 FFmpeg - Out-of-Bounds Write in RASC Decoder decode_dlta() — FFmpeg CWE-787 8.6 High 2026-06-28
CVE-2026-8461 Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder — FFmpeg CWE-787 8.8 High 2026-06-18

This page lists every published CVE security advisory associated with FFMPEG. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.