VULNERABILITY INTELLIGENCE
CVE-2016-10192
CVSS score9.8 CRITICAL
EPSS probability6.55%
CISA KEVNot currently listed
Published2017-02-09
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.
Weakness classification
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Primary references
- cve@mitre.org — Mailing List, Patch, Third Party Advisory
- cve@mitre.org — Mailing List, Patch, Third Party Advisory
- cve@mitre.org — Third Party Advisory, VDB Entry
- cve@mitre.org — Release Notes, Vendor Advisory
- cve@mitre.org — Patch
- af854a3a-2127-422b-91ae-364da2661108 — Mailing List, Patch, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Mailing List, Patch, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Release Notes, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Patch