Ffjpeg
Vendor:
First CVE: Sep 10, 2018 · Active for 7 years
19
Total CVEs
More Total CVEs than 95% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ffjpeg over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 10, 2018
7 years ago
Most Recent CVE
Aug 11, 2023
1,082 days ago
CVE Severity & Scoring
Ffjpeg19 CVEs
95%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (26.3%)
Network14 (73.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (5.3%)
Unknown0 (0.0%)
Required18 (94.7%)
Privileges Required
Low1 (5.3%)
High0 (0.0%)
None18 (94.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24222HIGH Buffer Overflow vulnerability in jfif_decode() function in rockcarry ffjpeg through version 1.0.0, allows local attackers to execute arbitrary code due to an issue with ALIGN. | Aug 11, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-28471MEDIUM In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfi | May 5, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-45385MEDIUM A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the bmp is out of range, it returns without as | Feb 11, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-44957MEDIUM Global buffer overflow vulnerability exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23705. Issue is in the jfif_encode function at ffjpeg/src/jfif.c (line 708) could | Feb 8, 2022 | 6.5 | 22 | NO | NO |
CVE-2020-23705MEDIUM A global buffer overflow vulnerability in jfif_encode at jfif.c:701 of ffjpeg through 2020-06-22 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file. | Jul 15, 2021 | 6.5 | 22 | NO | NO |
CVE-2019-16351MEDIUM ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c. | Sep 16, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-16350MEDIUM ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c. | Sep 16, 2019 | 6.5 | 22 | NO | NO |
CVE-2018-16781MEDIUM ffjpeg.dll in ffjpeg before 2018-08-22 allows remote attackers to cause a denial of service (FPE signal) via a progressive JPEG file that lacks an AC Huffman table. | Sep 10, 2018 | 6.5 | 22 | NO | NO |
CVE-2019-16352MEDIUM ffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c. | Sep 16, 2019 | 6.5 | 21 | NO | NO |
CVE-2021-34122MEDIUM The function bitstr_tell at bitstr.c in ffjpeg commit 4ab404e has a NULL pointer dereference. | Mar 10, 2022 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Ffjpeg
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2021-12-06 | 2 | 6.5 | 0.9% | 0 | 0 |