Known Vulnerabilities for Ffmpeg-sdk by Ffmpeg-sdk Project
Listed below are 1 of the newest known vulnerabilities associated with "Ffmpeg-sdk" by "Ffmpeg-sdk Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64835 json | FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavc... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-64834 json | FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_a... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-64833 json | FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to ... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-64832 json | FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-64831 json | FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that all... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-64830 json | FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows at... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-63305 json | AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callb... | Not Provided | 2026-07-16 | 2026-07-20 |
| CVE-2026-58049 json | FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the ... | Not Provided | 2026-06-28 | 2026-07-22 |
| CVE-2026-55173 json | WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the f... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-48793 json | Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability e... | Not Provided | 2026-06-24 | 2026-06-26 |