CVE-2016-6920: Ffmpeg

High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of service (application crash) via vectors involving tile positions.

Affected products

  • Ffmpeg Ffmpeg: up to and including 3.1.2

Published 2017-01-23. Last modified 2026-06-17.