Libavformat is a multimedia container and format-parsing library embedded across media players, transcoding tools, and streaming applications, where its role in deserializing untrusted media files creates a broad exposure surface despite a narrow product footprint. The observed vulnerability pattern centers on integer overflow and out-of-bounds read conditions within format-parsing logic, reflecting the complexity of handling diverse and often malformed media container structures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libavformat Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5115MEDIUM The avcodec_decode_audio4 function in libavcodec in libavformat 57.34.103, as used in MPlayer, allows remote attackers to cause a denial of service (out-of-bounds read) via a craft | Feb 3, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-4352MEDIUM Integer overflow in the demuxer function in libmpdemux/demux_gif.c in Mplayer allows remote attackers to cause a denial of service (crash) via large dimensions in a gif file. | Feb 3, 2017 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libavformat Project.
Media articles that mention a CVE ID that affects a product developed by Libavformat Project — matched by CVE ID, not by vendor name.