<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:34:27.351926+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05549</id>
    <title>bdu:2026-05549</title>
    <updated>2026-10-03T02:34:27.388726+00:00</updated>
    <content>bdu:2026-05549</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05549"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-291583</id>
    <title>EUVD-2026-291583</title>
    <updated>2026-10-03T02:34:27.388766+00:00</updated>
    <content>EUVD-2026-291583</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-291583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40962</id>
    <title>fkie_cve-2026-40962</title>
    <updated>2026-10-03T02:34:27.388781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-48wr-p98v-9w5h</id>
    <title>GHSA-48wr-p98v-9w5h</title>
    <updated>2026-10-03T02:34:27.388811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-48wr-p98v-9w5h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2928</id>
    <title>OESA-2026-2928 — ffmpeg security update</title>
    <updated>2026-10-03T02:34:27.388826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: ffmpeg</p>
<p>FFmpeg is a complete and free Internet live audio and video broadcasting solution for Linux/Unix. It also includes a digital VCR. It can encode in real time in many formats including MPEG1 audio and video, MPEG4, h263, ac3, asf, avi, real, mjpeg, and flash.

Security Fix(es):</p>
<p>An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.(CVE-2026-30997)</p>
<p>FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.(CVE-2026-40962)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10767-1</id>
    <title>openSUSE-SU-2026:10767-1 — ffmpeg-4-4.4.6-12.1 on GA media</title>
    <updated>2026-10-03T02:34:27.388853+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ffmpeg-4-4.4.6-12.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10767-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:74089</id>
    <title>RHSA-2026:74089 — Red Hat Security Advisory: RHEL AI 3.0 RPM runtime CVE fix - ffmpeg</title>
    <updated>2026-10-03T02:34:27.388871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ffmpeg: FFmpeg: Remote code execution via out-of-bounds write in MagicYUV decoder FFmpeg: FFmpeg: Integer overflow and out-of-bounds write via CENC subsample data FFmpeg: FFmpeg: Memory corruption via crafted RASC video stream ffmpeg: FFmpeg: Arbitrary code execution via heap buffer overflow in VobSub subtitle demuxer. FFmpeg: Denial of Service via crafted RTP/ASF stream FFmpeg: FFmpeg: Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files ffmpeg: FFmpeg: Arbitrary code execution via crafted video in vf_hqdn3d filter ffmpeg: FFmpeg: Arbitrary code execution via crafted CAF file</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:74089"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40962</id>
    <title>UBUNTU-CVE-2026-40962</title>
    <updated>2026-10-03T02:34:27.388905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libav, Ubuntu:Pro:20.04:LTS: ffmpeg, Ubuntu:Pro:22.04:LTS: ffmpeg, Ubuntu:Pro:24.04:LTS: ffmpeg, Ubuntu:25.10: ffmpeg, Ubuntu:Pro:26.04:LTS: ffmpeg</p>
<p>FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1143</id>
    <title>WID-SEC-W-2026-1143 — ffmpeg: Mehrere Schwachstellen</title>
    <updated>2026-10-03T02:34:27.388931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in ffmpeg ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen oder um einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1143"/>
  </entry>
</feed>
