Libav is a focused multimedia framework library used extensively across media players, streaming services, and video-processing applications for codec and container handling, despite maintaining a single core product. The library's vulnerability exposure concentrates on memory-safety and input-parsing weaknesses—including buffer-boundary violations, NULL-pointer dereferences, out-of-bounds reads, and improper input validation—that arise from the complexity of decoding diverse and untrusted media formats. Because Libav is deeply embedded in software supply chains rather than deployed as a standalone service, individual vulnerabilities can propagate broadly to downstream consumers, making the vendor a critical node for defenders inventorying media-stack risks. Defenders should track Libav's releases closely and ensure that products bundling the library receive timely updates, as remediation typically requires downstream rebuilds and redeployment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libav over time
Signals from CVEs in this vendor scope (108 CVEs).
108 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9051CRITICAL libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c. | May 18, 2017 | 9.8 | 30 | NO | NO |
CVE-2012-2772HIGH Unspecified vulnerability in the ff_rv34_decode_frame function in libavcodec/rv34.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact a | Sep 10, 2012 | 10.0 | 30 | NO | NO |
CVE-2016-3062HIGH The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbi | Jun 16, 2016 | 8.8 | 29 | NO | NO |
CVE-2011-3937HIGH The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6 | Jan 5, 2013 | 10.0 | 29 | NO | NO |
CVE-2012-5144HIGH Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of ser | Dec 12, 2012 | 10.0 | 29 | NO | NO |
CVE-2012-2803HIGH Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact an | Sep 10, 2012 | 10.0 | 29 | NO | NO |
CVE-2012-2801HIGH Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to dimensio | Sep 10, 2012 | 10.0 | 29 | NO | NO |
CVE-2012-2798HIGH Unspecified vulnerability in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack | Sep 10, 2012 | 10.0 | 29 | NO | NO |
CVE-2012-2793HIGH Unspecified vulnerability in the lag_decode_zero_run_line function in libavcodec/lagarith.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown | Sep 10, 2012 | 10.0 | 29 | NO | NO |
CVE-2012-2786HIGH Unspecified vulnerability in the decode_wdlt function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack | Sep 10, 2012 | 10.0 | 29 | NO | NO |
Signals from CVEs in this vendor scope (108 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libav.
Media articles that mention a CVE ID that affects a product developed by Libav — matched by CVE ID, not by vendor name.