CVE-2016-7393: Libav

Medium severity, CVSS 5.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the aac_sync function in aac_parser.c in Libav before 11.5 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

Affected products

  • Libav Libav: up to and including 11.4

Published 2017-02-15. Last modified 2026-06-17.