FFmpeg is a ubiquitously embedded multimedia framework whose single core product sits in the software supply chain across countless video players, transcoding services, streaming platforms, and content-management systems. Its vulnerability footprint, despite a narrow product base, reflects the complexity of multimedia decoding and encoding: memory-safety issues dominate the exposure, with recurring weaknesses including buffer boundary violations, out-of-bounds reads and writes, and input-validation gaps that arise across the codec and demultiplexer layers. A meaningful share of the vendor's disclosures reach serious severity, reflecting the memory-unsafe implementation patterns inherent to performance-critical codec work. Defenders should treat FFmpeg updates as broadly applicable given the library's deep embedding in downstream products; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ffmpeg over time
Signals from CVEs in this vendor scope (497 CVEs).
497 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4637HIGH FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow. | Feb 10, 2010 | 10.0 | 45 | NO | YES |
CVE-2026-8461HIGH An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote | Jun 18, 2026 | 8.8 | 44 | NO | NO |
CVE-2026-64835HIGH FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out | Jul 22, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-64832HIGH FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corrupt | Jul 22, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-64831HIGH FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and | Jul 22, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-64830HIGH FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a | Jul 22, 2026 | 8.8 | 38 | NO | NO |
CVE-2008-3162HIGH Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash) | Jul 14, 2008 | 9.3 | 37 | NO | YES |
CVE-2026-64834HIGH FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of se | Jul 22, 2026 | 7.5 | 34 | NO | NO |
CVE-2016-10192CRITICAL Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code b | Feb 9, 2017 | 9.8 | 34 | NO | NO |
CVE-2026-65706HIGH FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted N | Jul 23, 2026 | 7.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (497 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ffmpeg.
Media articles that mention a CVE ID that affects a product developed by Ffmpeg — matched by CVE ID, not by vendor name.