Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ffmpeg

First CVE: Dec 7, 2005Active for: 21 yearsTotal CVEs: 497
46.6
VTI Score
High

FFmpeg is a ubiquitously embedded multimedia framework whose single core product sits in the software supply chain across countless video players, transcoding services, streaming platforms, and content-management systems. Its vulnerability footprint, despite a narrow product base, reflects the complexity of multimedia decoding and encoding: memory-safety issues dominate the exposure, with recurring weaknesses including buffer boundary violations, out-of-bounds reads and writes, and input-validation gaps that arise across the codec and demultiplexer layers. A meaningful share of the vendor's disclosures reach serious severity, reflecting the memory-unsafe implementation patterns inherent to performance-critical codec work. Defenders should treat FFmpeg updates as broadly applicable given the library's deep embedding in downstream products; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
497
Total CVEs
More Total CVEs than 100% of tracked vendors
5.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ffmpeg over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 7, 2005
20 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (497 CVEs).

497 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-4637HIGH
FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow.
Feb 10, 201010.045NOYES
CVE-2026-8461HIGH
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote
Jun 18, 20268.844NONO
CVE-2026-64835HIGH
FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out
Jul 22, 20268.838NONO
CVE-2026-64832HIGH
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corrupt
Jul 22, 20268.838NONO
CVE-2026-64831HIGH
FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and
Jul 22, 20268.838NONO
CVE-2026-64830HIGH
FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a
Jul 22, 20268.838NONO
CVE-2008-3162HIGH
Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash)
Jul 14, 20089.337NOYES
CVE-2026-64834HIGH
FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of se
Jul 22, 20267.534NONO
CVE-2016-10192CRITICAL
Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code b
Feb 9, 20179.834NONO
CVE-2026-65706HIGH
FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted N
Jul 23, 20267.833NONO
View all 497 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products497 CVEs
44%
49%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local84 (16.9%)
Network199 (40.0%)
Unknown210 (42.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low278 (55.9%)
High9 (1.8%)
Unknown210 (42.3%)
User Interaction
None88 (17.7%)
Unknown210 (42.3%)
Required195 (39.2%)
Privileges Required
Low18 (3.6%)
High0 (0.0%)
None269 (54.1%)
Unknown210 (42.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (497 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
0.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ffmpeg.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ffmpeg — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ffmpeg's Products

View all 11 CNAs →

Top CWEs