CVE-2015-1208: Ffmpeg

Medium severity, CVSS 5.5. EPSS: 1.5% chance of exploitation in the next 30 days.

Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.

Affected products

  • Ffmpeg Ffmpeg: before 2.4.6 (fixed in 2.4.6)

Published 2018-01-09. Last modified 2026-06-17.