A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond
the bounds of a heap-allocated buffer when processing crafted TDSC cursor
data. A remote attacker could exploit this by supplying a specially crafted
video file, potentially leading to a denial of service or arbitrary code
execution.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 12:16
Updated : 2026-08-28 20:17
NVD link : CVE-2026-18393
Mitre link : CVE-2026-18393
CVE.ORG link : CVE-2026-18393
JSON object : View
Products Affected
No product.
CWE
CWE-787
Out-of-bounds Write
