<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:10:01 +0000</lastBuildDate>
    <item>
      <title>cnvd-2026-34246</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-34246</link>
      <description>cnvd-2026-34246</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-34246</guid>
    </item>
    <item>
      <title>EUVD-2026-352717</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352717</link>
      <description>EUVD-2026-352717</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352717</guid>
    </item>
    <item>
      <title>fkie_cve-2026-70630</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-70630</link>
      <description>&lt;p&gt;FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx-&amp;gt;inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx-&amp;gt;inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-70630</guid>
    </item>
    <item>
      <title>GHSA-7mrq-j773-6867</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7mrq-j773-6867</link>
      <description>&lt;p&gt;FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx-&amp;gt;inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx-&amp;gt;inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7mrq-j773-6867</guid>
    </item>
    <item>
      <title>OESA-2026-3541 — ffmpeg security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3541</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: ffmpeg&lt;/p&gt;
&lt;p&gt;FFmpeg is a complete and free Internet live audio and video broadcasting solution for Linux/Unix. It also includes a digital VCR. It can encode in real time in many formats including MPEG1 audio and video, MPEG4, h263, ac3, asf, avi, real, mjpeg, and flash.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.(CVE-2026-30998)&lt;/p&gt;
&lt;p&gt;FFmpeg&amp;amp;apos;s RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.(CVE-2026-58049)&lt;/p&gt;
&lt;p&gt;FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub-&amp;amp;gt;q[] array boundary via ff_subtitles_queue_insert(), potentially achiev…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: ffmpeg&lt;/p&gt;
&lt;p&gt;FFmpeg is a complete and free Internet live audio and video broadcasting solution for Linux/Unix. It also includes a digital VCR. It can encode in real time in many formats including MPEG1 audio and video, MPEG4, h263, ac3, asf, avi, real, mjpeg, and flash.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.(CVE-2026-30998)&lt;/p&gt;
&lt;p&gt;FFmpeg&amp;amp;apos;s RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.(CVE-2026-58049)&lt;/p&gt;
&lt;p&gt;FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub-&amp;amp;gt;q[] array boundary via ff_subtitles_queue_insert(), potentially achiev…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3541</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11659-1 — ffmpeg-9-libavcodec-devel-9.0.1-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11659-1</link>
      <description>&lt;p&gt;ffmpeg-9-libavcodec-devel-9.0.1-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ffmpeg-9-libavcodec-devel-9.0.1-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11659-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-70630</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-70630</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libav, Ubuntu:Pro:16.04:LTS: ffmpeg, Ubuntu:Pro:18.04:LTS: ffmpeg, Ubuntu:Pro:20.04:LTS: ffmpeg, Ubuntu:Pro:22.04:LTS: ffmpeg, Ubuntu:Pro:24.04:LTS: ffmpeg, Ubuntu:Pro:26.04:LTS: ffmpeg&lt;/p&gt;
&lt;p&gt;FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx-&amp;gt;inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libav, Ubuntu:Pro:16.04:LTS: ffmpeg, Ubuntu:Pro:18.04:LTS: ffmpeg, Ubuntu:Pro:20.04:LTS: ffmpeg, Ubuntu:Pro:22.04:LTS: ffmpeg, Ubuntu:Pro:24.04:LTS: ffmpeg, Ubuntu:Pro:26.04:LTS: ffmpeg&lt;/p&gt;
&lt;p&gt;FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx-&amp;gt;inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-70630</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2700 — ffmpeg: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2700</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in ffmpeg ausnutzen, um beliebigen Programmcode auszuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in ffmpeg ausnutzen, um beliebigen Programmcode auszuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2700</guid>
    </item>
  </channel>
</rss>
