Flvmeta is a utility for analyzing and manipulating FLV (Flash Video) file metadata, with a narrow but specialized deployment footprint in media processing and archival workflows. Its vulnerability profile centers on memory-safety issues inherent to its C implementation, with recurring exposure to classic buffer overflows and use-after-free conditions in parsing and metadata-handling routines. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flvmeta over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36243HIGH FLVMeta v1.2.1 was discovered to contain a buffer overflow via the xml_on_metadata_tag_only function at dump_xml.c. | Jun 22, 2023 | 7.8 | 20 | NO | NO |
CVE-2024-25385MEDIUM An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close. | Feb 22, 2024 | 6.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flvmeta.
Media articles that mention a CVE ID that affects a product developed by Flvmeta — matched by CVE ID, not by vendor name.