CVE-2014-2098: Ffmpeg

Medium severity, CVSS 6.8. EPSS: 1.8% chance of exploitation in the next 30 days.

libavcodec/wmalosslessdec.c in FFmpeg before 2.1.4 uses an incorrect data-structure size for certain coefficients, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted WMA data.

Affected products

  • Ffmpeg Ffmpeg: up to and including 2.1.3; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.1 only; …

Published 2014-03-02. Last modified 2026-06-17.