Search CVE reports


Toggle filters

1 – 10 of 347 results


CVE-2026-30999

Medium priority
Needs evaluation

A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2026-30998

Medium priority
Needs evaluation

An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2026-30997

Medium priority
Needs evaluation

An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2025-69693

Medium priority
Not affected

Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release
ffmpeg Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-12343

Negligible priority
Needs evaluation

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling...

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2025-63757

Medium priority

Some fixes available 6 of 8

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release
ffmpeg Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-59734

Medium priority
Needs evaluation

It is possible to cause an use-after-free write in SANM decoding with a carefully crafted animation using subversion <2. When a STOR chunk is present, a subsequent FOBJ chunk will be saved in ctx->stored_frame. Stored frames can...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release
ffmpeg Ignored Ignored Ignored Ignored
Show less packages

CVE-2025-59733

Medium priority

Some fixes available 5 of 7

When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that all image channels have the same pixel type (and size), and that if there are four channels, the first four are "B", "G",...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release
ffmpeg Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-59732

Medium priority

Some fixes available 3 of 5

When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that the height and width are divisible by 8. If the height or width of the image is not divisible by 8, the copy loops at [0] and...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release
ffmpeg Fixed Fixed Not affected Not affected
Show less packages

CVE-2025-59731

Medium priority

Some fixes available 3 of 5

When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to calculate the output data. We read rle_raw_size from the input file at [0], we...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release
ffmpeg Fixed Fixed Not affected Not affected
Show less packages