Ffjpeg

Vendor:

First CVE: Sep 10, 2018 · Active for 7 years

19
Total CVEs
More Total CVEs than 95% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ffjpeg over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 10, 2018
7 years ago
Most Recent CVE
Aug 11, 2023
1,082 days ago

CVE Severity & Scoring

Ffjpeg19 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local5 (26.3%)
Network14 (73.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (5.3%)
Unknown0 (0.0%)
Required18 (94.7%)
Privileges Required
Low1 (5.3%)
High0 (0.0%)
None18 (94.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer Overflow vulnerability in jfif_decode() function in rockcarry ffjpeg through version 1.0.0, allows local attackers to execute arbitrary code due to an issue with ALIGN.
Aug 11, 20237.825NONO
In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfi
May 5, 20226.522NONO
A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the bmp is out of range, it returns without as
Feb 11, 20226.522NONO
Global buffer overflow vulnerability exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23705. Issue is in the jfif_encode function at ffjpeg/src/jfif.c (line 708) could
Feb 8, 20226.522NONO
A global buffer overflow vulnerability in jfif_encode at jfif.c:701 of ffjpeg through 2020-06-22 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.
Jul 15, 20216.522NONO
ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.
Sep 16, 20196.522NONO
ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.
Sep 16, 20196.522NONO
ffjpeg.dll in ffjpeg before 2018-08-22 allows remote attackers to cause a denial of service (FPE signal) via a progressive JPEG file that lacks an AC Huffman table.
Sep 10, 20186.522NONO
ffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c.
Sep 16, 20196.521NONO
The function bitstr_tell at bitstr.c in ffjpeg commit 4ab404e has a NULL pointer dereference.
Mar 10, 20225.520NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Ffjpeg

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2021-12-0626.50.9%00