Ffmpeg
This hub aggregates every CVE we track for Ffmpeg, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
532
CVEs tracked
107
Critical
170
High
0
In CISA KEV
Severity distribution
MEDIUM247HIGH170CRITICAL107LOW8
Monthly trend
0
9
2
6
9
1
0
1
0
0
1
1
7
1
1
0
2
1
4
0
2
16
12
4
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Ffmpeg.
- CVE-2026-96611FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds ...6.9
- CVE-2026-52297FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.2.9
- CVE-2026-52296FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.2.9
- CVE-2026-52295FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.2.9
- CVE-2026-75147FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c7.1
- CVE-2026-75146FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c8.1
- CVE-2026-75145FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer5.8
- CVE-2026-75144FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer7.8
- CVE-2026-75143FFmpeg Heap Buffer Overflow via RIST Protocol Reader9.8
- CVE-2026-75142FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c7.8
- CVE-2026-75141FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing7.8
- CVE-2026-70632FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing7.8
- CVE-2026-70631FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder5.5
- CVE-2026-70630FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder5.5
- CVE-2026-70629FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder5.5
Product normalization is registry-driven with AI assist and human review. How it works