CVE-2020-14212: Ffmpeg

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted.

Affected products

  • Ffmpeg Ffmpeg: from 4.3, before 4.3.1 (fixed in 4.3.1)

Published 2020-06-16. Last modified 2026-06-17.