CVE-2019-11339: Ffmpeg
High severity, CVSS 8.8. EPSS: 2.8% chance of exploitation in the next 30 days.
The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via crafted MPEG-4 video data.
Affected products
- Ffmpeg Ffmpeg: from 4.0, before 4.0.4 (fixed in 4.0.4); from 4.1, before 4.1.2 (fixed in 4.1.2)
Published 2019-04-19. Last modified 2026-06-17.