CVE-2013-4358: Ffmpeg

Medium severity, CVSS 5.0. EPSS: 1.3% chance of exploitation in the next 30 days.

libavcodec/h264.c in FFmpeg before 0.11.4 allows remote attackers to cause a denial of service (crash) via vectors related to alternating bit depths in H.264 data.

Affected products

  • Ffmpeg Ffmpeg: up to and including 0.11.3; version 0.11 only; version 0.11.1 only; version 0.11.2 only

Published 2013-12-24. Last modified 2026-06-16.