Skip to content
Threat Feed

Tag

Media-Processing

4 briefs RSS
medium advisory

Multiple Denial of Service Vulnerabilities in FFmpeg

Multiple vulnerabilities in the FFmpeg multimedia framework can be exploited by a remote, anonymous attacker to trigger a Denial of Service condition, leading to service disruption.

FFmpeg vulnerability denial-of-service media-processing
1t
high advisory

FFmpeg TDSC Video Decoder Out-of-Bounds Write Vulnerability

An out-of-bounds write vulnerability (CVE-2026-65703) exists in the TDSC video decoder within FFmpeg versions 2.7 through 8.1.2, allowing remote attackers to cause heap corruption and potential code execution by supplying a specially crafted AVI file with changing frame dimensions across TDSF frames.

FFmpeg 2.7 +1 vulnerability media-processing code-execution
1t 1c
high advisory

FFmpeg Vulkan HEVC Stack Buffer Overflow (CVE-2026-64831)

A stack buffer overflow vulnerability exists in the Vulkan HEVC hardware decoder within FFmpeg versions 8.0 through 8.1.2, allowing remote attackers to achieve arbitrary code execution by crafting a malicious HEVC/H.265 bitstream with an oversized vps_num_hrd_parameters value that overwrites return addresses and adjacent stack frames in the vk_hevc_end_frame function.

FFmpeg vulnerability buffer-overflow media-processing arbitrary-code-execution
1t 1c
high advisory

MediaArea MediaInfoLib Channel Splitting Heap-Based Buffer Overflow (CVE-2026-22554)

MediaArea MediaInfoLib is vulnerable to a heap-based buffer overflow vulnerability when splitting channels, potentially leading to arbitrary code execution.

MediaInfoLib heap-based buffer overflow cve-2026-22554 media processing
2r 1t 1c