Search CVE reports


Toggle filters

1 – 10 of 522 results


CVE-2025-9951

Medium priority
Needs evaluation

A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2025-8585

Medium priority
Vulnerable

A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release
ffmpeg Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-8586

Medium priority
Vulnerable

A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_frame_binary of the file /libavformat/utils.c of the component MPEG File Parser. The manipulation leads to null...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release
ffmpeg Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-8584

Medium priority
Vulnerable

A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function av_buffer_unref of the file libavutil/buffer.c of the component AVI File Parser. The manipulation leads to...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release
ffmpeg Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-7700

Medium priority
Needs evaluation

[NULL Pointer Dereference in FFmpeg ALS Decoder (libavcodec/alsdec.c)]

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2024-55069

Medium priority
Vulnerable

ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release Not in release
ffmpeg Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2025-1816

Medium priority

Some fixes available 1 of 2

A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This affects the function audio_element_obu of the file libavformat/iamf_parse.c of the component IAMF File...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release Not in release
ffmpeg Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-1594

Medium priority

Some fixes available 6 of 7

A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release Not in release
ffmpeg Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-25473

Medium priority

Some fixes available 7 of 8

FFmpeg git master before commit c08d30 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release Not in release
ffmpeg Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-25471

Medium priority
Needs evaluation

FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release Not in release
ffmpeg Not affected Not affected Not affected Not affected
Show less packages