Vulnerabilities in FFMPEG
45 resultsVexday analysis
FFmpeg apresenta footprint mínimo na base Vexday com apenas 1 CVE crítica registrada, atualmente sem evidência de exploração ativa no KEV. A vulnerabilidade identificada (CWE-122: Buffer Overflow) representa risco clássico em processamento de mídia, mas sua ausência em ataques observados e falta de atualizações recentes sugerem controle adequado ou adoção lenta do vetor. Recomenda-se validar se a exposição reflete uso efetivo em ambiente produtivo.
CVE-2026-75145MEDIUMFFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP PacketizerEPSS 0.2%CVE-2026-40962MEDIUMFFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.cEPSS 0.2%CVE-2026-52297LOWFFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libEPSS 0.2%CVE-2026-52296LOWFFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.EPSS 0.2%CVE-2026-96611MEDIUMFFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF iEPSS 0.1%