Ffmpeg
532 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Ffmpeg, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Ffmpeg CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 9 |
| 2024-12 | 2 |
| 2025-01 | 6 |
| 2025-02 | 9 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 1 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 1 |
| 2025-10 | 7 |
| 2025-11 | 1 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 2 |
| 2026-03 | 1 |
| 2026-04 | 4 |
| 2026-05 | 0 |
| 2026-06 | 2 |
| 2026-07 | 16 |
| 2026-08 | 12 |
| 2026-09 | 4 |
Severity
How the 532 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical107
- High170
- Medium247
- Low8
Latest CVEs
The 15 most recently published vulnerabilities affecting Ffmpeg.
- CVE-2026-96611FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds ...6.9
- CVE-2026-52297FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.2.9
- CVE-2026-52296FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.2.9
- CVE-2026-52295FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.2.9
- CVE-2026-75147FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c7.1
- CVE-2026-75146FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c8.1
- CVE-2026-75145FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer5.8
- CVE-2026-75144FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer7.8
- CVE-2026-75143FFmpeg Heap Buffer Overflow via RIST Protocol Reader9.8
- CVE-2026-75142FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c7.8
- CVE-2026-75141FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing7.8
- CVE-2026-70632FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing7.8
- CVE-2026-70631FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder5.5
- CVE-2026-70630FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder5.5
- CVE-2026-70629FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder5.5
Product grouping is registry-driven, with AI assist and human review. How it works