CVE Tools

Libav

93 CVEs tracked since 2011. Since Jul 2011, none of them reached CISA KEV.

Libav CVEs per month

Jul 2011 to Aug 2021. Point at a month, or focus the strip and use the arrow keys.
Libav CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2011-0710
2011-08null or fewer
2011-09null or fewer
2011-1010
2011-11null or fewer
2011-12null or fewer
2012-01null or fewer
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-07null or fewer
2012-08160
2012-09230
2012-10null or fewer
2012-11null or fewer
2012-1210
2013-0110
2013-02null or fewer
2013-03null or fewer
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-07null or fewer
2013-08null or fewer
2013-09null or fewer
2013-10null or fewer
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-0610
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-1110
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-0610
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-0410
2016-05null or fewer
2016-0610
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-1010
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-0260
2017-03100
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-1240
2018-0130
2018-02null or fewer
2018-0360
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-1040
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-0750
2019-08null or fewer
2019-0930
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-0830

Products

The products that kept showing up in Libav's monthly top three, with their CVEs summed over those months.

  1. Libav9321 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Libav.

  1. CVE-2025-8586libav MPEG File Parser utils.c ff_seek_frame_binary null pointer dereference3.3
  2. CVE-2025-8585libav DSS File Demuxer avconv.c main double free5.3
  3. CVE-2025-8584libav AVI File Parser buffer.c av_buffer_unref null pointer dereference3.3
  4. CVE-2020-18776In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.6.5
  5. CVE-2020-18778In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.6.5
  6. CVE-2020-18775In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.6.5
  7. CVE-2014-4609Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.2 allows remote attackers to execute arbitrary code via a crafted Literal Run.8.8
  8. CVE-2019-9720A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misu...6.5
  9. CVE-2019-9719A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misu...8.8
  10. CVE-2019-9717In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex forma...6.5
  11. CVE-2019-14443An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by ...6.5
  12. CVE-2019-14442In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to c...6.5
  13. CVE-2019-14441An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ff_mpa_synth_filte...6.5
  14. CVE-2019-14372In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.6.5
  15. CVE-2019-14371An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.6.5

The record

Peak rank
#6 in Sep 2012
Busiest month shown
Sep 2012, 23 CVEs
Months with a KEV entry
0 since Jul 2011
Monthly snapshots
21 since 2011
Libav's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store