Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

DSA-4990-1

Published Oct 19, 2021·Last modified Mar 9, 2026
Affected Components(0)

No affected components available

Description

ffmpeg - security update

Risk Scores
Base Score
0.0

Measures severity based on intrinsic characteristics of the vulnerability, independent of environment.

Threat Intelligence
0.0

No exploitation activity has been observed at this time. Continue routine monitoring.

EPSS
2.69%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Related Vulnerabilities
  • CVE-2020-20445

    FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/lpc.h, which allows a remote malicious user to cause a Denial of Service.

    UpstreamEPSS 1.6%
  • CVE-2020-20446

    FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aacpsy.c, which allows a remote malicious user to cause a Denial of Service.

    UpstreamEPSS 1.7%
  • CVE-2020-20453

    FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aaccoder, which allows a remote malicious user to cause a Denial of Service

    UpstreamEPSS 1.8%
  • CVE-2020-21041

    Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service

    UpstreamEPSS 2.1%
  • CVE-2020-22015

    Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.

    UpstreamEPSS 2.5%
  • CVE-2020-22016

    A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.h when writing .mov files, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.6%
  • CVE-2020-22017

    A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/drawutils.c, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.4%
  • CVE-2020-22019

    Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service.

    UpstreamEPSS 1.1%
  • CVE-2020-22020

    Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause a Denial of Service.

    UpstreamEPSS 1.5%
  • CVE-2020-22021

    Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service.

    UpstreamEPSS 1.7%
  • CVE-2020-22022

    A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.7%
  • CVE-2020-22023

    A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_bitplanenoise.c, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.4%
  • CVE-2020-22025

    A heap-based Buffer Overflow vulnerability exists in gaussian_blur at libavfilter/vf_edgedetect.c, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.8%
  • CVE-2020-22026

    Buffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function at libavfilter/af_tremolo.c, which could let a remote malicious user cause a Denial of Service.

    UpstreamEPSS 1.4%
  • CVE-2020-22027

    A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighbor.c, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.5%
  • CVE-2020-22028

    Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_vertically_8 at libavfilter/vf_avgblur.c, which could cause a remote Denial of Service.

    UpstreamEPSS 1.7%
  • CVE-2020-22029

    A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.5%
  • CVE-2020-22030

    A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/af_afade.c in crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.2%
  • CVE-2020-22031

    A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_w3fdif.c in filter16_complex_low, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.7%
  • CVE-2020-22032

    A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.8%
  • CVE-2020-22033

    A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a remote malicious user cause a Denial of Service.

    UpstreamEPSS 1.5%
  • CVE-2020-22034

    A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_floodfill.c, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.6%
  • CVE-2020-22035

    A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.2%
  • CVE-2020-22036

    A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c, which might lead to memory corruption and other potential consequences.

    UpstreamEPSS 1.7%
  • CVE-2020-22037

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.

    UpstreamEPSS 1.6%
  • CVE-2020-22049

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.

    UpstreamEPSS 1.3%
  • CVE-2020-22054

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.

    UpstreamEPSS 1.3%
  • CVE-2020-35965
    Upstream
  • CVE-2021-38114

    libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a similar issue to CVE-2013-0868.

    UpstreamEPSS 1.0%
  • CVE-2021-38171

    adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted.

    UpstreamEPSS 2.4%
  • CVE-2021-38291

    FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.

    UpstreamEPSS 2.7%
  • EUVD-2020-13232
    Upstream
  • EUVD-2020-13233
    Upstream
  • EUVD-2020-13240
    Upstream
  • EUVD-2020-13820
    Upstream
  • EUVD-2020-14781
    Upstream
  • EUVD-2020-14782
    Upstream
  • EUVD-2020-14783
    Upstream
  • EUVD-2020-14785
    Upstream
  • EUVD-2020-14786
    Upstream
  • EUVD-2020-14787
    Upstream
  • EUVD-2020-14788
    Upstream
  • EUVD-2020-14789
    Upstream
  • EUVD-2020-14791
    Upstream
  • EUVD-2020-14792
    Upstream
  • EUVD-2020-14793
    Upstream
  • EUVD-2020-14794
    Upstream
  • EUVD-2020-14795
    Upstream
  • EUVD-2020-14796
    Upstream
  • EUVD-2020-14797
    Upstream
  • EUVD-2020-14798
    Upstream
  • EUVD-2020-14799
    Upstream
  • EUVD-2020-14800
    Upstream
  • EUVD-2020-14801
    Upstream
  • EUVD-2020-14802
    Upstream
  • EUVD-2020-14803
    Upstream
  • EUVD-2020-14815
    Upstream
  • EUVD-2020-14820
    Upstream
  • EUVD-2020-23548
    Upstream
  • EUVD-2021-24587
    Upstream
  • EUVD-2021-24641
    Upstream
  • EUVD-2021-24749
    Upstream
Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard