CVE-2018-7751: Ffmpeg

Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.

The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file.

Affected products

  • Ffmpeg Ffmpeg: up to and including 3.4.2

Published 2018-04-24. Last modified 2026-06-17.