Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-72cw-2m7j-25c8

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.

EPSS

Процентиль: 3%
0.00137
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.8
ubuntu
8 дней назад

(FFmpeg before commit acf5d7c contains a heap buffer overflow in the hv ...)

CVSS3: 7.8
nvd
8 дней назад

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.

CVSS3: 7.8
debian
8 дней назад

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hv ...

EPSS

Процентиль: 3%
0.00137
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-122