CVE-2016-6164: Ffmpeg

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving sample size.

Affected products

  • Ffmpeg Ffmpeg: up to and including 2.8.7; version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.1 only

Published 2017-01-23. Last modified 2026-06-17.