Search CVE reports


Toggle filters

1 – 10 of 341 results


CVE-2025-59734

Medium priority
Needs evaluation

It is possible to cause an use-after-free write in SANM decoding with a carefully crafted animation using subversion <2. When a STOR chunk is present, a subsequent FOBJ chunk will be saved in ctx->stored_frame. Stored frames can...

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2025-59733

Medium priority
Needs evaluation

When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that all image channels have the same pixel type (and size), and that if there are four channels, the first four are "B", "G",...

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2025-59732

Medium priority
Needs evaluation

When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that the height and width are divisible by 8. If the height or width of the image is not divisible by 8, the copy loops at [0] and...

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2025-59731

Medium priority
Needs evaluation

When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to calculate the output data. We read rle_raw_size from the input file at [0], we...

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2025-59730

Medium priority
Needs evaluation

When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it. Frames encoded with codec 48 can specify their resolution (width x height). A buffer of appropriate size is...

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2025-59729

Medium priority
Needs evaluation

When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the duration from before the start of the allocated buffer. If we load a DHAV file that is larger than...

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2025-59728

Medium priority
Needs evaluation

When calculating the content path in handling of MPEG-DASH manifests, there's an out-of-bounds NUL-byte write one byte past the end of the buffer.When we call xmlNodeGetContent below [0], it returns a buffer precisely allocated to...

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release
Show less packages

CVE-2025-10256

Medium priority
Vulnerable

[Unknown description]

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Vulnerable Vulnerable Vulnerable Vulnerable
libav Not in release Not in release
Show less packages

CVE-2025-9951

Medium priority
Vulnerable

A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.

2 affected packages

ffmpeg, libav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Vulnerable Vulnerable Vulnerable Vulnerable
libav Not in release Not in release
Show less packages

CVE-2025-8585

Medium priority
Vulnerable

A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double...

2 affected packages

libav, ffmpeg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libav Not in release Not in release
ffmpeg Not affected Not affected Not affected Not affected
Show less packages