CVE-2017-9051: Libav

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c.

Affected products

  • Libav Libav: up to and including 12.0

Published 2017-05-18. Last modified 2026-06-17.