Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 17 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | FFmpeg: FFmpeg: Integer overflow and out-of-bounds write via CENC subsample data | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 16 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Apr 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c. | |
| First Time appeared |
Ffmpeg
Ffmpeg ffmpeg |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ffmpeg
Ffmpeg ffmpeg |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-16T12:31:48.767Z
Reserved: 2026-04-16T01:33:36.641Z
Link: CVE-2026-40962
Updated: 2026-04-16T12:20:14.391Z
Status : Analyzed
Published: 2026-04-16T02:16:12.227
Modified: 2026-04-20T19:54:35.317
Link: CVE-2026-40962
OpenCVE Enrichment
Updated: 2026-04-17T06:00:09Z