Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-75146

Опубликовано: 19 авг. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

EPSS

Процентиль: 18%
0.00261
Низкий

8.1 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 8.1
ubuntu
8 дней назад

(FFmpeg before commit 65b0dab contains an out-of-bounds read in the DAS ...)

CVSS3: 8.1
debian
8 дней назад

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DAS ...

CVSS3: 8.1
github
8 дней назад

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

EPSS

Процентиль: 18%
0.00261
Низкий

8.1 High

CVSS3

Дефекты

CWE-125