Mediaarea develops media-analysis and format-parsing utilities, particularly MediaInfo and its underlying ZenLib library, which are embedded across media processing pipelines and forensic tools. The vulnerability profile clusters around memory-safety issues inherent to parsing untrusted media files: out-of-bounds reads and writes, heap-based buffer overflows, integer underflows, and NULL-pointer dereferences reflect the parsing complexity and C++ implementation common to codecs and container formats. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mediaarea over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28764HIGH MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability | May 21, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-22554HIGH MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability | May 20, 2026 | 7.8 | 32 | NO | NO |
CVE-2026-25104HIGH MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability | May 26, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-25713HIGH MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability | May 26, 2026 | 7.8 | 30 | NO | NO |
CVE-2020-26797HIGH Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping. | Mar 18, 2021 | 7.5 | 25 | NO | NO |
CVE-2020-15395HIGH In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing | Jun 30, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-36646HIGH A vulnerability classified as problematic has been found in MediaArea ZenLib up to 0.4.38. This affects the function Ztring::Date_From_Seconds_1970_Local of the file Source/ZenLib/ | Jan 7, 2023 | 7.5 | 24 | NO | NO |
CVE-2019-11373MEDIUM An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash. | Apr 20, 2019 | 6.5 | 23 | NO | NO |
CVE-2019-11372MEDIUM An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash. | Apr 20, 2019 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mediaarea.
Media articles that mention a CVE ID that affects a product developed by Mediaarea — matched by CVE ID, not by vendor name.