CVE Tools

Ffmpeg

532 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Ffmpeg, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Ffmpeg CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Ffmpeg CVEs per month
MonthCVEs
2024-100
2024-119
2024-122
2025-016
2025-029
2025-031
2025-040
2025-051
2025-060
2025-070
2025-081
2025-091
2025-107
2025-111
2025-121
2026-010
2026-022
2026-031
2026-044
2026-050
2026-062
2026-0716
2026-0812
2026-094

Severity

How the 532 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical10720%
  • High17032%
  • Medium24746%
  • Low82%

Latest CVEs

The 15 most recently published vulnerabilities affecting Ffmpeg.

  1. CVE-2026-96611FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds ...6.9
  2. CVE-2026-52297FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.2.9
  3. CVE-2026-52296FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.2.9
  4. CVE-2026-52295FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.2.9
  5. CVE-2026-75147FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c7.1
  6. CVE-2026-75146FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c8.1
  7. CVE-2026-75145FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer5.8
  8. CVE-2026-75144FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer7.8
  9. CVE-2026-75143FFmpeg Heap Buffer Overflow via RIST Protocol Reader9.8
  10. CVE-2026-75142FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c7.8
  11. CVE-2026-75141FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing7.8
  12. CVE-2026-70632FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing7.8
  13. CVE-2026-70631FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder5.5
  14. CVE-2026-70630FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder5.5
  15. CVE-2026-70629FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder5.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store