Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/ffmpeg/FFmpeg

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in FFmpeg's Convolution Filter component (function setup_3x3 in libavfilter/vf_convolution.c) allows an out-of-bounds read. This issue affects versions up to 4.4.6, 5.1.8, 6.1.4, 7.1.3, and 8.0.1. The vulnerability can be exploited remotely and has been publicly disclosed. Upgrading to fixed versions resolves the issue.

Join the discussion

A denial of service vulnerability exists in FFmpeg 8.0.x within the parse_playlist function of libavformat/hlsproto.c. This issue is triggered by manipulating the duration or target_duration arguments. The vulnerability can be exploited remotely and causes a denial of service condition. Upgrading to FFmpeg versions 8.1 or 9.0 mitigates the issue.

Join the discussion
0

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.

Join the discussion
0

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-of-bounds read. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.7, 5.1.9, 6.1.5, 7.1.4, 8.0.2, 8.1.1 and 9.0 can resolve this issue. The name of the patch is 8970658472/e24b9820b4. It is suggested to upgrade the affected component.

Join the discussion

FFmpeg versions prior to 9.0 contain an out-of-bounds read vulnerability due to missing required padding in the WMA extradata allocation paths within the libavcodec/wmaenc.c file. This flaw can cause a denial of service but does not impact confidentiality or integrity.

Join the discussion

FFmpeg versions prior to 9.0 contain an out-of-bounds read vulnerability due to insufficient padding of extradata in the MOV parsing path within the mov_read_iacb function in libavformat/mov.c. This flaw can cause a denial of service but does not impact confidentiality or integrity.

Join the discussion

A security advisory from Red Hat addresses vulnerabilities in the ffmpeg component used in Red Hat Enterprise Linux AI 3.4 and 3.6. The advisory covers CVE-2026-64834 among others, which are rated with high severity. These vulnerabilities affect RPM packages that are internal build artifacts supported only as part of the Red Hat AI application platform. The advisory provides updated packages to remediate the issues.

Join the discussion
CVE-2026-30754: n/aCVE-2026-30754
0

A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP using a crafted input file. This was detected using AddressSanitizer.

Join the discussion

A buffer overflow vulnerability exists in Ffmpeg version 7.0 and later in the libavformat/iamf_writer.c component. This flaw can be exploited by an attacker to cause a denial of service (DoS) condition. The vulnerability does not impact confidentiality or integrity but affects availability.

Join the discussion

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder. This flaw allows an attacker who can supply a crafted TIFF file with a valid Deflate-compressed strip that decompresses fewer bytes than declared to cause stale heap data to be included in the decoded image output. This may lead to exposure of sensitive data in persistent services using the affected decoder.

Join the discussion

Showing 1 to 10 of 57 results

Filters:Package: pkg:github/ffmpeg/FFmpeg
Page 1 of 6
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses